Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix
A denial-of-service vulnerability exists in Rockwell Automation ControlLogix 5580, CompactLogix 5380, CompactLogix 5480, GuardLogix 5580, and Compact GuardLogix 5380 controllers. An attacker can send a specially crafted EtherNet/IP message to the controller, causing it to enter an infinite loop or exhaust resources, rendering the device unresponsive until restarted. This affects multiple firmware versions across these controller families. The vulnerability requires only network access to the controller's Ethernet port and does not require authentication or user interaction.
- Network access to the controller on its Ethernet port (port 44818 or 2222 EtherNet/IP by default)
- No authentication or valid credentials required
Patching may require device reboot — plan for process interruption
/api/v1/advisories/c4902133-50f1-40d1-82a2-2492a648afb2Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.