Rockwell Automation Logix Platform
Rockwell Automation Logix platform controllers are vulnerable to a buffer overflow in firmware versions V33 through V36.012 across ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380 product lines. A remote attacker without authentication can send a specially crafted network packet to trigger the vulnerability, causing the PLC to crash and stop executing control logic. The vulnerability is classified as CWE-119 (improper restriction of operations within the bounds of a memory buffer). Rockwell Automation has released patched firmware versions: V37.011 for all product lines, with interim patches available at V34.015, V35.014, and V36.013. Customers unable to apply firmware updates should implement network segmentation and access controls as compensating measures.
- Network access to the PLC on standard industrial protocols (Ethernet/IP)
- No authentication required to trigger the vulnerability
- PLC must be running an affected firmware version
Patching may require device reboot — plan for process interruption
/api/v1/advisories/9c6cf1be-eeda-4242-89e2-821d70bbe20bGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.