Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix

MonitorCVSS 7.5ICS-CERT ICSA-26-244-05Sep 1, 2026
Rockwell Automation
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A denial-of-service vulnerability exists in Rockwell Automation ControlLogix 5580, CompactLogix 5380, CompactLogix 5480, GuardLogix 5580, and Compact GuardLogix 5380 controllers. An attacker can send a specially crafted EtherNet/IP message to the controller, causing it to enter an infinite loop or exhaust resources, rendering the device unresponsive until restarted. This affects multiple firmware versions across these controller families. The vulnerability requires only network access to the controller's Ethernet port and does not require authentication or user interaction.

What this means
What could happen
A remote attacker can send specially crafted network packets to a Rockwell Automation controller (ControlLogix, CompactLogix, GuardLogix) causing the device to stop responding and halt production or safety-critical processes until manually restarted.
Who's at risk
Water and electric utilities, food and beverage producers, chemical plants, and other manufacturers using Rockwell Automation ControlLogix, CompactLogix, GuardLogix, or Compact GuardLogix programmable logic controllers (PLCs) for process automation and safety control. Any facility relying on these controllers for critical process monitoring, motor control, or safety interlocks is affected.
How it could be exploited
An attacker with network access to the controller's Ethernet port sends a malformed message that triggers an infinite loop or resource exhaustion condition in the firmware. The controller becomes unresponsive, and normal operation cannot resume without a restart. No credentials or authentication are required.
Prerequisites
  • Network access to the controller on its Ethernet port (port 44818 or 2222 EtherNet/IP by default)
  • No authentication or valid credentials required
remotely exploitableno authentication requiredlow complexityaffects safety systems (GuardLogix)default network protocols exposed
Exploitability
Some exploitation risk — EPSS score 3.4%
Public Proof-of-Concept (PoC) on GitHub (1 repository)
Affected products (21)
20 with fix1 pending
ProductAffected VersionsFix Status
ControlLogix 5580 <34.015<34.015Fix available
ControlLogix 5580 <35.014<35.014Fix available
ControlLogix 5580 <36.013<36.013Fix available
ControlLogix 5580 <37.011<37.011Fix available
GuardLogix 5580 <34.015<34.015Fix available
Remediation & Mitigation
0/7
Do now
0/2
WORKAROUNDRestrict network access to controller Ethernet ports using a firewall or network segmentation; allow only trusted engineering workstations and authorized systems
HARDENINGDisable remote access to controllers from untrusted networks if not operationally required
Schedule — requires maintenance window
0/5

Patching may require device reboot — plan for process interruption

HOTFIXUpdate ControlLogix 5580 to firmware version 34.015 or later (or 35.014 or later if running 35.x, 36.013 or later if running 36.x, 37.011 or later if running 37.x)
HOTFIXUpdate CompactLogix 5380 to firmware version 34.015 or later (or 35.014, 36.013, or 37.011 as applicable to your current version)
HOTFIXUpdate CompactLogix 5480 to firmware version 34.015 or later (or 35.014, 36.013, or 37.011 as applicable)
HOTFIXUpdate GuardLogix 5580 to firmware version 34.015 or later (or 35.014, 36.013, or 37.011 as applicable)
HOTFIXUpdate Compact GuardLogix 5380 to firmware version 34.015 or later (or 35.014, 36.013, or 37.011 as applicable)
API: /api/v1/advisories/c4902133-50f1-40d1-82a2-2492a648afb2

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix | CVSS 7.5 - OTPulse