Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module

MonitorCVSS 5.9ICS-CERT ICSA-26-211-05Jul 14, 2026
Rockwell Automation
Summary

CompactLogix 5380 and ControlLogix 5580 PLCs equipped with 1756-EN4 communications modules do not validate certificate revocation lists (CRL) when establishing network connections. This means a revoked or compromised certificate will be accepted as valid, allowing an unauthorized user with the certificate to connect to the PLC as if they were legitimate. The vulnerability affects all versions of these products, and Rockwell Automation has not announced plans to release a firmware patch.

What this means
What could happen
The communications module cannot validate whether network certificates have been revoked, allowing an attacker with a compromised certificate to maintain unauthorized network connections to your PLC or network. This could enable persistent access to alter control logic or monitor production operations.
Who's at risk
Water authorities and municipal utilities operating Rockwell CompactLogix 5380 or ControlLogix 5580 PLCs with 1756-EN4 communications modules should assess this vulnerability. Facilities using these systems for SCADA, process control, or water treatment equipment are affected across all firmware versions.
How it could be exploited
An attacker obtains a compromised or forged certificate that would normally be revoked. The PLC's communications module fails to check the certificate revocation list (CRL), accepting the bad certificate as valid. The attacker then establishes a network connection to the PLC and can interact with it as if authorized, potentially sending commands or extracting configuration data.
Prerequisites
  • Network access to the PLC on the port used for secure communications (typically port 443 or vendor-specific encrypted protocol port)
  • A compromised, forged, or expired certificate that the target organization would normally consider invalid
  • Knowledge of the PLC's network address and communication protocol
No patch availableRemotely exploitableAffects control system communications
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (7)
6 with fix1 EOL
ProductAffected VersionsFix Status
CompactLogix 5380 ControlLogix 5580 / 1756-EN4 Communications ModuleAll versionsNo fix (EOL)
Compact GuardLogix 5380: >=V36|<=V37≥ V36|≤ V3738.011
1756-EN4TR: V6.001V6.0018.001
1756-EN4TR: V7.001V7.0018.001
ControlLogix 5580: >=V36|<=V37≥ V36|≤ V3738.011
CompactLogix 5380: >=V36|<=V37≥ V36|≤ V3738.011
GuardLogix 5580: >=V36|<=V37≥ V36|≤ V3738.011
Remediation & Mitigation
0/4
Do now
0/2
HARDENINGReview and restrict network access to CompactLogix 5380 and ControlLogix 5580 communication ports using firewalls—allow only known engineering workstations and authorized remote access IP addresses
WORKAROUNDDisable any EtherNet/IP or remote access features if not required for your process
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HARDENINGMonitor audit logs on affected PLCs for unexpected incoming connection attempts or certificate validation errors
Mitigations - no patch available
0/1
CompactLogix 5380 ControlLogix 5580 / 1756-EN4 Communications Module has reached End of Life. The vendor will not release a patch. Apply the following compensating controls:
HARDENINGImplement a network segmentation strategy to isolate PLC networks from untrusted external networks and the Internet
API: /api/v1/advisories/26724575-8f5f-4266-b2b3-ca62b912ffdc

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.