Rockwell Automation Logix Platform

Plan PatchCVSS 7.5ICS-CERT ICSA-26-244-03Sep 1, 2026
Rockwell Automation
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Rockwell Automation Logix platform controllers are vulnerable to a buffer overflow in firmware versions V33 through V36.012 across ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380 product lines. A remote attacker without authentication can send a specially crafted network packet to trigger the vulnerability, causing the PLC to crash and stop executing control logic. The vulnerability is classified as CWE-119 (improper restriction of operations within the bounds of a memory buffer). Rockwell Automation has released patched firmware versions: V37.011 for all product lines, with interim patches available at V34.015, V35.014, and V36.013. Customers unable to apply firmware updates should implement network segmentation and access controls as compensating measures.

What this means
What could happen
An attacker with network access to a ControlLogix, CompactLogix, GuardLogix, or Compact GuardLogix controller could cause a denial of service by crashing the PLC firmware, halting production and control logic execution until the device is manually restarted.
Who's at risk
Water authorities and utilities operating Rockwell Automation ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, or Compact GuardLogix 5380 PLCs should assess their firmware versions immediately. These controllers are commonly used for SCADA, pump station control, pressure regulation, water treatment, and power distribution automation. Any PLC running an affected firmware version is at risk of denial of service.
How it could be exploited
An attacker on the same network as the PLC sends a specially crafted packet to the Logix device. The device processes the malformed input and crashes due to a buffer overflow vulnerability. The PLC reboots, interrupting all active control logic and process automation.
Prerequisites
  • Network access to the PLC on standard industrial protocols (Ethernet/IP)
  • No authentication required to trigger the vulnerability
  • PLC must be running an affected firmware version
Remotely exploitableNo authentication requiredLow complexity attackAffects safety-critical systems (GuardLogix is safety-rated)Denial of service to critical infrastructure operations
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (17)
17 with fix
ProductAffected VersionsFix Status
ControlLogix 5580 <=V33≤ V33Fix available
ControlLogix 5580 V34.011-V34.014V34.011-V34.014Fix available
ControlLogix 5580 V35.011-V35.013V35.011-V35.013Fix available
ControlLogix 5580 V36.011-V36.012V36.011-V36.012Fix available
CompactLogix 5380 <=V33≤ V33Fix available
Remediation & Mitigation
0/9
Do now
0/1
WORKAROUNDRestrict network access to PLC ports using firewall rules; permit only traffic from authorized engineering workstations and SCADA servers
Schedule — requires maintenance window
0/7

Patching may require device reboot — plan for process interruption

HOTFIXUpdate ControlLogix 5580 to firmware version V37.011 or later
HOTFIXUpdate CompactLogix 5380 to firmware version V37.011 or later
HOTFIXUpdate GuardLogix 5580 to firmware version V37.011 or later
HOTFIXUpdate Compact GuardLogix 5380 to firmware version V37.011 or later
HOTFIXIf running V34.x, update to firmware version V34.015 or later as an interim measure
HOTFIXIf running V35.x, update to firmware version V35.014 or later as an interim measure
HOTFIXIf running V36.x, update to firmware version V36.013 or later as an interim measure
Long-term hardening
0/1
HARDENINGSegment the PLC onto a dedicated industrial control network isolated from corporate IT and guest networks
API: /api/v1/advisories/9c6cf1be-eeda-4242-89e2-821d70bbe20b

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Rockwell Automation Logix Platform | CVSS 7.5 - OTPulse