PatchSiren cyber security CVE debrief
CVE-2025-24478 Rockwell Automation CVE debrief
CVE-2025-24478 is a denial-of-service vulnerability in Rockwell Automation GuardLogix 5380 and 5580 controllers. According to CISA’s advisory, a remote, non-privileged user can send malicious requests that trigger a major nonrecoverable fault, taking the affected controller out of service. Rockwell and CISA recommend updating to the fixed versions and applying OT access controls where possible.
- Vendor
- Rockwell Automation
- Product
- GuardLogix 5580 (SIL 3 with the safety partner 3)
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-02-04
- Original CVE updated
- 2025-02-18
- Advisory published
- 2025-02-04
- Advisory updated
- 2025-02-18
Who should care
OT/ICS security teams, plant operators, system integrators, and maintenance staff responsible for Rockwell Automation GuardLogix 5380 or 5580 SIL 3 controllers. This matters most in environments where controller availability is safety- or production-critical.
Technical summary
CISA’s CSAF advisory ICSA-25-035-02 describes a DoS condition affecting eight product/version combinations across GuardLogix 5580 (SIL 3 with the safety partner 3) and Compact GuardLogix 5380 SIL 3. The issue can be reached by a remote, non-privileged actor sending malicious requests, resulting in a major nonrecoverable fault and loss of availability. Affected versions are listed as below V33.017, V34.014, V35.013, or V36.011, depending on the product line. The advisory was initially published on 2025-02-04 and updated on 2025-02-18 (Update A) to revise the title, product list, and versions.
Defensive priority
Medium by CVSS (6.5), but higher operational priority in production OT environments because the affected controllers can fault and stop service. Treat as a prompt remediation item for any site using the listed versions.
Recommended defensive actions
- Upgrade to the fixed versions listed in the advisory: V33.017, V34.014, V35.013, or V36.011, or later as applicable to the installed product.
- Restrict access to the task object using CIP Security and Hard Run, as recommended by the advisory.
- Apply Rockwell Automation’s published security best practices and CISA ICS recommended practices to reduce exposure while patching is planned.
- Use environment-specific prioritization methods such as CISA SSVC to rank affected systems and schedule remediation in a controlled maintenance window.
Evidence notes
Primary evidence comes from CISA’s CSAF advisory ICSA-25-035-02 (published 2025-02-04, Update A on 2025-02-18), which names the affected Rockwell Automation GuardLogix 5380 and 5580 products, lists the fixed versions, and describes the remote non-privileged DoS condition. The CVE record is also linked in the official references. No exploit details beyond the advisory description are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-24478 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-24478
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-24478 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-24478
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-035-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-035-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.