Executive brief
Rockwell Automation CompactLogix 5370 controllers, which are used to manage industrial machinery and automation processes, contain a security flaw in their built-in web server. The web server publicly displays internal connection identifiers to any user on the network without requiring a password. An attacker can use this information to target the controller with malicious traffic, potentially causing the device to crash or stop functioning, which could disrupt industrial operations.
Technical details
A sensitive information disclosure vulnerability exists in the web server component of Rockwell Automation CompactLogix 5370 controllers (firmware V36). The diagnostics webpage improperly exposes Common Industrial Protocol (CIP) Connection IDs to unauthenticated users via the network. While this disclosure is passive, these IDs are critical parameters required to craft malicious CIP packets. An attacker can leverage this leaked information to bypass certain session protections and initiate a Denial-of-Service (DoS) attack against the controller. The issue is addressed in firmware version V38.011.
Affected products
- Rockwell Automation CompactLogix 5370 L1 V36
- Rockwell Automation CompactLogix 5370 L2 V36
- Rockwell Automation CompactLogix 5370 L3 V36
Timeline
- 2026-06-16: disclosed
- 2026-06-16: advisory
- 2026-06-16: patched