Junglewise Threat Intelligence

CVE-2026-12659: Rockwell Automation FLEX 5000 Adapter denial of service via crafted CIP packets

CVE-2026-12659 · Severity: info · CVSS 8.7 · Published 2026-07-14

Vendors: Rockwell Automation.

Executive brief

Rockwell Automation FLEX 5000 EtherNet/IP Adapters are used to connect industrial I/O modules to automation networks. A security vulnerability has been identified that allows a remote attacker to crash the adapter, causing a total loss of communication and control over the connected industrial equipment. Recovering from this state requires a physical power cycle of the hardware, which could lead to significant operational downtime in manufacturing or utility environments.

Technical details

A denial-of-service (DoS) vulnerability exists in the Rockwell Automation FLEX 5000 EtherNet/IP Adapter firmware version 6.011. The issue is classified as a double-free vulnerability (CWE-415) triggered by improper handling of exceptional conditions during the processing of specially crafted Common Industrial Protocol (CIP) packets. An unauthenticated attacker can send these packets over the network to cause the adapter to enter a non-responsive state. Recovery of the module and its associated I/O requires a manual power cycle. The vulnerability is addressed in firmware version 6.012.

Affected products

  • Rockwell Automation FLEX 5000 EtherNet/IP Adapter 6.011

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory
  • 2026-07-14: patched: Fixed in version 6.012

References