news.mlab.sh
Back to the feed
vulnerability

Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix

High
Summary

Several vulnerabilities exist in Rockwell Automation's CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controllers. Successful exploitation could lead to a denial-of-service condition due to an invalid project load, causing the device to enter a major non-recoverable fault (MNRF). These vulnerabilities are present in controllers with boot firmware versions lower than 1.072. Rockwell recommends updating to firmware versions V35.016, V36.011 and later, as well as V34.014, V35.013, V36.011 and later, among others.

Rockwell Automation has issued an advisory regarding critical vulnerabilities in its CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controllers. These vulnerabilities could be exploited to cause a denial-of-service condition by allowing a malicious user to write invalid file data to the controller, resulting in a major non-recoverable fault (MNRF). The vulnerabilities are present in controllers with boot firmware versions lower than 1.072.

Specifically, the advisory details several CVEs including CVE-2025-12011, CVE-2025-12012, CVE-2025-11698, CVE-2025-12011, CVE-2025-12012, CVE-2025-11698, CVE-2025-12011, CVE-2025-12012, CVE-2025-11698, CVE-2025-12011, CVE-2025-12012, CVE-2025-11698, CVE-2025-12011, CVE-2025-12012, CVE-2025-11698, CVE-2025-12011, CVE-2025-12012, CVE-2025-11698, CVE-2025-12011, CVE-2025-12012, CVE-2025-11698.

Rockwell Automation recommends updating to the following firmware versions to remediate these vulnerabilities: CompactLogix 5370: V35.016, V36.011 and later; Compact GuardLogix 5370: V35.016, V36.011 and later; ControlLogix 5570: V35.016, V36.011 and later; GuardLogix 5570: V35.016, V36.011 and later; CompactLogix 5380: V34.014, V35.013, V36.011 and later; Compact GuardLogix 5380: V34.014, V35.013, V36.011 and later; CompactLogix 5480: V34.014, V35.013, V36.011 and later; ControlLogix 5580: V34.014, V35.013, V36.011 and later; GuardLogix 5580: V34.014, V35.013, V36.011 and later; CompactLogix 5380 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed; Compact GuardLogix 5380 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed; CompactLogix 5480 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed; ControlLogix 5580 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed; GuardLogix 5580 Recovery Image: Update to boot firmware 1.072 or greater. If using V36.013, V37.011 or later, already has corrected boot firmware is installed.

CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. These measures include minimizing network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet, locating control system networks and remote devices behind firewalls and isolating them from business networks.

Read the full article at CISA Advisories