Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix

Plan PatchCVSS 8.6ICS-CERT ICSA-26-197-06Jul 14, 2026
Rockwell Automation
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Rockwell CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controllers contain a buffer overflow vulnerability in their network communication stack. All versions of CompactLogix and ControlLogix are affected. Exploitation could allow remote code execution on the PLC. No vendor fix is currently available.

What this means
What could happen
A buffer overflow in Rockwell PLCs could allow an attacker to execute arbitrary code on the controller, potentially disrupting production processes, altering safety logic, or causing uncontrolled equipment operation.
Who's at risk
This affects water utilities and electric utilities operating Rockwell CompactLogix or ControlLogix controllers in supervisory, process control, and safety logic applications. Any site using these PLCs for motor control, pump operation, valve sequencing, or safety shutdown systems should take this seriously.
How it could be exploited
An attacker with network access to the PLC's engineering port (typically Ethernet) can send a specially crafted packet to trigger the buffer overflow. Successful exploitation allows code execution on the PLC with the same privileges as the control application.
Prerequisites
  • Network access to the PLC's Ethernet port (typically port 2222 for RSLinx communications or industrial protocols)
  • No credentials typically required to exploit buffer overflows at the transport layer
remotely exploitableno authentication requiredno patch availableaffects safety systems
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (20)
19 with fix1 EOL
ProductAffected VersionsFix Status
CompactLogix , ControlLogixAll versionsNo fix (EOL)
CompactLogix 5370≤ V35.01535.016
Compact GuardLogix 5370≤ V35.01535.016
ControlLogix 5570≤ V35.01535.016
GuardLogix 5570≤ V35.01535.016
Remediation & Mitigation
0/4
Do now
0/2
HARDENINGRestrict network access to Rockwell PLCs using a firewall—allow only trusted engineering workstations and HMI systems to reach the controller's Ethernet port
WORKAROUNDDisable remote engineering access (RSLinx over Ethernet) if not actively in use; use local serial or USB connections for configuration when possible
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXMonitor for any available firmware or patch updates from Rockwell Automation and test in a lab environment before deployment
Mitigations - no patch available
0/1
CompactLogix , ControlLogix has reached End of Life. The vendor will not release a patch. Apply the following compensating controls:
HARDENINGImplement network segmentation to isolate PLC subnets from the corporate network and untrusted plant floor networks
API: /api/v1/advisories/91e4ce6c-8e6e-4c1f-b00d-a7c1a9f48118

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.