Rockwell Automation Studio 5000 Logix Designer
MonitorCVSS 7.5ICS-CERT ICSA-26-202-10Jul 14, 2026
Rockwell Automation
Summary
Studio 5000 Logix Designer (all versions) contains multiple input validation vulnerabilities that could allow an attacker to modify PLC program logic or firmware. An attacker with access to a development workstation or project files could inject malicious code that would execute on production controllers, potentially altering process control behavior, disabling alarms, or corrupting safety interlocks.
What this means
What could happen
An attacker could modify PLC program logic or firmware during development or deployment, potentially altering setpoints, disabling safeties, or corrupting control sequences that govern critical processes in water treatment, power distribution, or manufacturing facilities.
Who's at risk
Water utilities, electric utilities, manufacturing plants, and any facility using Rockwell CompactLogix or ControlLogix PLCs programmed with Studio 5000 Logix Designer. Development and engineering teams, system integrators, and operations staff who deploy or maintain PLC logic are most directly affected.
How it could be exploited
An attacker with access to a development workstation running Studio 5000 Logix Designer could exploit input validation flaws in the application to inject malicious code into PLC projects. The modified project could then be downloaded to production PLCs, affecting real-world operations. Alternatively, an attacker could intercept or tamper with project files during transfer to alter control logic remotely.
Prerequisites
- Access to a workstation running Studio 5000 Logix Designer
- Ability to create, open, or modify PLC projects in the application
- Or network position to intercept project files being transferred to PLCs
No patch availableAffects PLC programming tools used across critical infrastructureCould impact safety systems if malicious logic is injected into safety controllers
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (13)
12 with fix1 EOL
ProductAffected VersionsFix Status
Studio 5000 Logix DesignerAll versionsNo fix (EOL)
Studio 5000 Logix Designer: V36.00V36.00Fix available
Studio 5000 Logix Designer: V35.00V35.00Fix available
Studio 5000 Logix Designer: V35.01V35.01Fix available
Studio 5000 Logix Designer: >=V34.00|<=V34.03≥ V34.00|≤ V34.03Fix available
Studio 5000 Logix Designer: >=V33.00|<=V33.03≥ V33.00|≤ V33.03Fix available
Studio 5000 Logix Designer: >=V32.00|<=V32.04≥ V32.00|≤ V32.04Fix available
Studio 5000 Logix Designer: V34.00V34.00Fix available
Remediation & Mitigation
0/5
Do now
0/2Studio 5000 Logix Designer
HARDENINGRestrict physical and network access to engineering workstations running Studio 5000 Logix Designer to authorized personnel only
All products
WORKAROUNDImplement file integrity monitoring on Studio 5000 project files to detect unauthorized modifications
Schedule — requires maintenance window
0/3Patching may require device reboot — plan for process interruption
HARDENINGRequire code review and version control for all PLC projects before deployment to production equipment
HARDENINGIsolate development networks from production control networks using network segmentation and firewall rules
HARDENINGEnable encryption and digital signing for PLC project files in transit between workstations and controllers
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/e38f08c5-0c6f-451d-9a76-d9da1a25922cGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.