Rockwell Automation ControlFLASH
MonitorCVSS 7.3ICS-CERT ICSA-26-246-03Sep 1, 2026
Rockwell Automation
Summary
Rockwell ControlFLASH contains an improper access control vulnerability that allows an attacker with network access to the device to perform unauthorized operations without authentication. The vulnerability affects all versions of ControlFLASH.
What this means
What could happen
An attacker on your network could connect directly to ControlFLASH and perform unauthorized firmware updates or configuration changes without credentials, potentially compromising controller logic and causing uncontrolled process behavior or shutdown.
Who's at risk
Plant engineers, maintenance staff, and control system operators managing Rockwell automation environments should be concerned. This affects any site using ControlFLASH for firmware management and programming of Rockwell PLCs, drives, and industrial controllers.
How it could be exploited
An attacker with network access to the ControlFLASH device can send commands directly to it without providing valid credentials. By crafting specially formed requests, the attacker can trigger firmware update or configuration operations, allowing them to modify or replace the firmware running on connected controllers.
Prerequisites
- Network access to ControlFLASH device port (typically TCP/IP)
- No authentication credentials required
remotely exploitableno authentication requiredno patch availableaffects control system firmware integrity
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (2)
1 pending1 EOL
ProductAffected VersionsFix Status
ControlFLASH All versionsNo fix (EOL)
ControlFLASH≤ V15.07No fix yet
Remediation & Mitigation
0/5
Do now
0/2ControlFLASH
HARDENINGRestrict network access to ControlFLASH devices using firewall rules; allow connections only from authorized engineering workstations on your control network
WORKAROUNDRestrict physical access to computers and devices running ControlFLASH to authorized personnel only
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
ControlFLASH
HARDENINGSegment ControlFLASH and programming devices onto a separate VLAN with access control lists limiting traffic to authorized users and systems only
All products
WORKAROUNDMonitor Rockwell security advisories and contact Rockwell support for updates on patch availability and additional mitigation options
Mitigations - no patch available
0/1ControlFLASH has reached End of Life. The vendor will not release a patch. Apply the following compensating controls:
HARDENINGImplement network monitoring to detect unauthorized connection attempts or firmware update operations on ControlFLASH devices
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/b00a2528-b139-4d58-a9d8-cd6c73423c0bGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.