Executive brief
Rockwell Automation Logix controllers, which are used to manage industrial machinery and automation processes, are vulnerable to a denial-of-service attack. An attacker can send a specially crafted network message that causes the controller to crash into a 'Major Non-Recoverable Fault' state. This results in an immediate halt of industrial operations and requires a manual program reload to restore service, potentially leading to significant production downtime.
Technical details
A denial of service vulnerability exists in Rockwell Automation Logix 5370 and 5570 controllers due to improper resource handling (CWE-404) when processing Common Industrial Protocol (CIP) messages. An unauthenticated remote attacker can send a crafted CIP message over the network to trigger a Major Non-Recoverable Fault (MNRF). Devices with lower memory specifications are reported to be more susceptible to this condition. Once the fault occurs, the controller stops executing its logic, and recovery requires a fresh program download. Firmware updates (versions 34.016, 35.015, 36.012, 37.011 and later) have been released to address the issue.
Affected products
- Rockwell Automation CompactLogix 5370 Prior to 34.016, 35.015, 36.012
- Rockwell Automation Compact GuardLogix 5370 Prior to 34.016, 35.015, 36.012
- Rockwell Automation ControlLogix 5570 Prior to 34.016, 35.015, 36.012
- Rockwell Automation GuardLogix 5570 Prior to 34.016, 35.015, 36.012
Timeline
- 2026-06-16: disclosed
- 2026-06-16: advisory
- 2026-06-16: patched