← Terug naar overzicht

A denial-of-service vulnerability (CVE-2026-9637) exists in multiple Rockwell Automation Logix Platform products due to improper validation of input length during CIP message processing. Affected products include ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380 across multiple firmware versions up to V36. Exploitation can cause a major nonrecoverable fault (MNRF), requiring a power cycle to restore operation. The vulnerability is remotely exploitable with no authentication or user interaction required, scoring 7.5 (HIGH) on CVSS v3.1 and 8.7 (HIGH) on CVSS v4.0. Rockwell Automation reported the issue to CISA and has released patched firmware versions (V34.015, V35.014, V36.013, V37.011). Organizations unable to patch are advised to follow Rockwell Automation security best practices and isolate control systems from internet exposure. No known public exploitation has been reported at the time of publication.

Affected products

  • Rockwell Automation Compact GuardLogix 5380
  • Rockwell Automation CompactLogix 5380
  • Rockwell Automation ControlLogix 5580
  • Rockwell Automation GuardLogix 5580

Related CVE's

  • CVE-2026-9637

Categories

  • Critical Infrastructure
  • Network Infrastructure