Executive brief
Rockwell Automation's Logix control systems—used in industrial automation for manufacturing and process control—contain a denial-of-service vulnerability in their CIP (Common Industrial Protocol) message handling. An attacker can exploit this by sending a specially crafted message, causing the controller to crash and enter an irrecoverable fault state that requires manual power cycling to restore, disrupting production operations.
Technical details
The vulnerability is a buffer overflow (CWE-119) in CIP message processing on Logix platforms. The root cause is improper validation of input length during message parsing, allowing an attacker to trigger a major nonrecoverable fault (MNRF) that crashes the controller. The attack is network-accessible and requires no authentication or user interaction. An attacker can repeatedly send malformed CIP messages to cause denial of service; remediation requires upgrading to corrected firmware versions (V37.011, V36.013, V35.014, or V34.015) for each affected product line.
Affected products
- Rockwell Automation ControlLogix 5580 V33 and prior, V34.011–V34.014, V35.011–V35.013, V36.011–V36.012
- Rockwell Automation CompactLogix 5380 V33 and prior, V34.011–V34.014, V35.011–V35.013, V36.011–V36.012
- Rockwell Automation GuardLogix 5580 V33 and prior, V34.011–V34.014, V35.011–V35.013, V36.011–V36.012
- Rockwell Automation CompactGuardLogix 5380 V33 and prior, V34.011–V34.014, V35.011–V35.013, V36.011–V36.012
Timeline
- 2026-09-01: disclosed: Security advisory SD1792 published by Rockwell Automation
- 2026-09-01: patched: Corrected firmware versions available: V37.011, V36.013, V35.014, V34.015
- 2026-09-01: kev added: Listed as Known Exploited Vulnerability (KEV)