Rockwell Automation Flex 5000 Adapter

MonitorCVSS 7.5ICS-CERT ICSA-26-197-08Jul 14, 2026
Rockwell Automation
Summary

The Flex 5000 Adapter is vulnerable to a denial of service attack. An attacker can send crafted network packets to the adapter, causing it to become unresponsive and stop processing communications. The vulnerability affects all versions of the Flex 5000 Adapter. Rockwell Automation has not released a patch and has stated no fix is planned.

What this means
What could happen
An attacker can remotely disable the Flex 5000 Adapter, causing it to stop processing communications from connected devices. This would interrupt data flow between your control systems and field devices, potentially halting production or affecting real-time process monitoring.
Who's at risk
Manufacturing facilities, water treatment plants, and electric utilities relying on Flex 5000 Adapters for communication between PLCs, RTUs, and field instrumentation. This affects any operation that depends on continuous data flow through this adapter for process control or monitoring.
How it could be exploited
An attacker with network access to the Flex 5000 Adapter can send specially crafted network packets that cause the adapter to become unresponsive or crash. Once triggered, the adapter stops relaying commands and telemetry between your controllers and field equipment until it is manually restarted.
Prerequisites
  • Network access to the Flex 5000 Adapter (typically on port 2222 or industrial Ethernet network)
  • No special credentials or authentication required
remotely exploitableno authentication requiredno patch availableaffects communications infrastructure
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (2)
1 with fix1 EOL
ProductAffected VersionsFix Status
Flex 5000 AdapterAll versionsNo fix (EOL)
Flex 5000 Adapter: 6.0116.011Fix available
Remediation & Mitigation
0/4
Do now
0/2
Flex 5000 Adapter
HARDENINGRestrict network access to the Flex 5000 Adapter using firewall rules, allowing only trusted engineering and control network segments to connect
HARDENINGDisable or isolate any unused network ports on the Flex 5000 Adapter
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HARDENINGMonitor the adapter for unexpected restarts or communication drops and configure alerts for anomalous activity
Mitigations - no patch available
0/1
Flex 5000 Adapter has reached End of Life. The vendor will not release a patch. Apply the following compensating controls:
HARDENINGImplement network segmentation to prevent untrusted devices and external networks from reaching the adapter
API: /api/v1/advisories/2258d85a-ef02-4860-9347-35768a3f16b8

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Rockwell Automation Flex 5000 Adapter | CVSS 7.5 - OTPulse