PatchSiren cyber security CVE debrief
CVE-2025-12011 Rockwell Automation CVE debrief
A denial-of-service issue exists in 5370/5570 controllers of Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter a major non-recoverable fault (MNRF). Organizations using these products should be aware of this vulnerability and take necessary actions to update to the recommended versions. The CVE record was published on 2026-07-16T06:00:00.000Z and has not been modified since then. Affected product deployments should be identified and owners assigned for follow-up. Official advisories and CVE records should be reviewed to validate affected scope, severity, and vendor guidance.
- Vendor
- Rockwell Automation
- Product
- CompactLogix 5370
- CVSS
- HIGH 8.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-16
- Original CVE updated
- 2026-07-16
- Advisory published
- 2026-07-16
- Advisory updated
- 2026-07-16
Who should care
Organizations using Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix should be aware of this vulnerability and take necessary actions to update to the recommended versions. Affected operators, platforms, and security teams should review the vulnerability and implement necessary mitigations. Vulnerability management and security teams should prioritize updating to the recommended versions to prevent potential denial-of-service attacks. Asset owners and operators should identify and prioritize affected deployments for remediation. Security teams should monitor for suspicious activity and implement incident response plans. Compensating controls, such as network segmentation and access controls, should be implemented to limit the attack surface. Change management processes should be followed for updates and patches. Source tracking and monitoring should be implemented to detect potential attacks. Asset inventory and rollback/change windows should be reviewed to ensure timely remediation. Security teams should review and update incident response plans to address this vulnerability. Security awareness and training programs should be updated to include information on this vulnerability and its potential impact. Compliance and regulatory requirements should be reviewed to ensure adherence to guidelines and standards for vulnerability management and remediation. Business continuity and disaster recovery plans should be reviewed to ensure they address potential denial-of-service attacks. Communication plans should be developed to inform stakeholders of the vulnerability and remediation efforts. Training and awareness programs should be implemented to educate users on the vulnerability and its potential impact. Patch management processes should be reviewed and updated to ensure timely application of patches and updates. Vulnerability scanning and penetration testing should be performed to identify and remediate potential vulnerabilities. Incident response plans should be tested and updated to ensure they are effective in addressing denial-of-service attacks. Security information and event management systems should be monitored for signs of
Technical summary
A denial-of-service issue exists in 5370/5570 controllers of Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter a major non-recoverable fault (MNRF). The vulnerability affects the specified controllers and could allow an attacker to cause a denial-of-service condition. Organizations should prioritize updating to the recommended versions to prevent potential denial-of-service attacks.
Defensive priority
Organizations using Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix should prioritize updating to the recommended versions to prevent potential denial-of-service attacks.
Recommended defensive actions
- Update to the recommended versions: CompactLogix 5370: V35.016, V36.011 and later; Compact GuardLogix 5370: V35.016, V36.011 and later; ControlLogix 5570: V35.016, V36.011 and later; GuardLogix 5570: V35.016, V36.011 and
- Implement compensating controls, such as network segmentation and access controls, to limit the attack surface.
- Monitor for suspicious activity and implement incident response plans.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
Evidence notes
The source corpus provides details on the vulnerability affecting Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix. A denial-of-service issue exists in 5370/5570 controllers, potentially allowing a remote user to load an invalid project, causing the device to enter a major non-recoverable fault (MNRF).
Official resources
-
CVE-2025-12011 CVE record
CVE.org
-
CVE-2025-12011 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-16T06:00:00.000Z and has not been modified since then.