PatchSiren

Rockwell Automation CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Rockwell Automation CVE published 2026-07-21

CVE-2026-9140

A denial-of-service security issue exists in the Rockwell Automation 1719-AENTR, caused by improper handling of a UDP unicast network storm, leading to device overload and loss of communication. This issue affects Industrial control system administrators and security teams responsible for Rockwell Automation 1718-AENTR/1719-AENTR devices. A power cycle is required to recover. The issue has a CVSS score of [truncated]

HIGH Rockwell Automation CVE published 2026-07-21

CVE-2026-9128

A code execution security issue exists within Studio 5000 Logix Designer due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. This vulnerability could allow [truncated]

HIGH Rockwell Automation CVE published 2026-07-21

CVE-2026-9127

A remote code execution security issue exists in Rockwell Automation Studio 5000 Logix Designer due to incorrect authorization on a configuration file. This allows any authenticated user to modify external tool paths, potentially leading to arbitrary code execution when interacting with external tools. Organizations using Rockwell Automation Studio 5000 Logix Designer, particularly those in industrial con [truncated]

MEDIUM Rockwell Automation CVE published 2026-07-21

CVE-2026-9108

A path traversal security issue exists within Studio 5000 Logix Designer due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project [truncated]

HIGH Rockwell Automation CVE published 2026-07-21

CVE-2026-10714

The Rockwell Automation FactoryTalk Services Platform (FTSP) is vulnerable to an issue allowing an attacker to bypass JWT signature validation during Okta Web Authentication. This occurs because FTSP does not verify that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to 'none' and craft forged tokens. Consequently, an authenticated low-privilege user could impersonate a [truncated]

HIGH Rockwell Automation CVE published 2026-07-21

CVE-2026-10573

A denial-of-service security issue exists in 1734 POINT I/O module from Rockwell Automation. The security issue stems from improper handling of crafted CIP messages, which can cause the module to enter a faulted state. A restart is required to recover. This issue affects various industrial control systems that use this module. Organizations using Rockwell Automation 1734 POINT I/O modules should be aware [truncated]

MEDIUM Rockwell Automation CVE published 2026-07-16

CVE-2026-9292

A Stored Cross-Site Scripting security issue exists within FactoryTalk DataMosaix Private Cloud due to improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject malicious scripts that are permanently stored on the server. This vulnerability can result in the execution of malicious JavaScript when other users access the affe [truncated]

HIGH Rockwell Automation CVE published 2026-07-16

CVE-2026-8314

A security issue exists within Arena Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.

HIGH Rockwell Automation CVE published 2026-07-16

CVE-2026-8313

A security issue exists within Arena Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.

HIGH Rockwell Automation CVE published 2026-07-16

CVE-2026-8312

A security issue exists within Arena Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.

HIGH Rockwell Automation CVE published 2026-07-16

CVE-2026-12659

A denial-of-service security issue exists in Rockwell Automation Flex 5000 Adapter. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent to the adapter. A power cycle is required to recover the module and associated I/O. This issue has significant implications for industrial control systems (ICS) environments, particularly those utilizing Rockw [truncated]

HIGH Rockwell Automation CVE published 2026-07-16

CVE-2025-12011

A denial-of-service issue exists in 5370/5570 controllers of Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter a major non-recoverable fault (MNRF). Organizations using these products should be aware of this vulnerability and take necessary actions to update to [truncated]

HIGH Rockwell Automation CVE published 2026-07-14

CVE-2026-11917

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T06:00:00.000Z and has not been modified since then. The NVD entry is currently High. This path traversal issue in Rockwell Automation ThinManager software could allow an authenticated attacker to write arbitrary files to restricted system directories outside of the application's intended director [truncated]

CRITICAL Rockwell Automation CVE published 2026-07-14

CVE-2026-10577

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-14T06:00:00.000Z and has not been modified since then. The Rockwell Automation 1715-AENTR EtherNet/IP Adapter is affected by a critical vulnerability that allows unauthenticated remote access to intrusive command-line interface (CLI) commands via a network-accessible debug port without proper privil [truncated]

HIGH Rockwell Automation CVE published 2026-06-18

CVE-2025-13036

CVE-2025-13036 is a critical authentication bypass vulnerability in FactoryTalk Historian Site Edition. An attacker can exploit this vulnerability by continually sending requests to the login endpoint, potentially obtaining a valid authentication token. The vulnerability has a CVSS score of 9.2 and is considered critical.

MEDIUM Rockwell Automation CVE published 2026-06-16

CVE-2026-9307

A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct malicious packets, leading to Denial-of-Service.

HIGH Rockwell Automation CVE published 2026-06-16

CVE-2026-11317

A denial of service security issue exists in the affected product. The security issue stems from a fault occurring when a crafted CIP message is sent. Devices with less memory are more likely to be affected. This can result in a major nonrecoverable fault (MNRF). A program download is required to recover.

CRITICAL Rockwell Automation CVE published 2026-06-16

CVE-2026-0647

CVE-2026-0647 is an improper authentication security issue within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated attacker to change the device's web interface password by sending a crafted HTTP GET request to a specific endpoint, without any prior authentication being required. If exploited, this could lead to unauthorized access, account takeover, and loss of th [truncated]

HIGH Rockwell Automation CVE published 2026-06-16

CVE-2026-0646

CVE-2026-0646 is a HIGH-severity denial-of-service vulnerability in the 1794-AENTR adapter. The issue arises from improper memory handling of CIP protocol requests, which can cause the adapter to fault and lose connection to its associated I/O modules. A manual reset is required to recover from this vulnerability. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 8.7.

HIGH Rockwell Automation CVE published 2026-06-16

CVE-2025-14272

CVE-2025-14272 is a HIGH-severity vulnerability (CVSS Score: 8.3) affecting an unknown vendor's product, potentially allowing unauthorized actors to execute privileged operations. The issue was published on 2026-06-16T15:16:33.000Z and last modified on 2026-06-16T15:26:04.250Z.

HIGH Rockwell Automation CVE published 2026-06-16

CVE-2025-11694

CVE-2025-11694 is a HIGH severity vulnerability with a CVSS score of 8.7. The vulnerability exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and source IP addresses in the CIP protocol. This allows an attacker to abuse the exposed Connection ID's visible on the web interface to perform denial-of-service attacks, resulting in a minor fault.

HIGH Rockwell Automation CVE published 2026-02-18

CVE-2020-11656

CVE-2020-11656 is a critical SQLite use-after-free issue cited by CISA for Rockwell Automation DataMosaix Private Cloud. The advisory states that affected versions are <=7.09 and that the issue is addressed in v7.11.01. Given the advisory’s 9.8 CVSS score and network-based attack model, organizations should prioritize remediation and ICS hardening.

HIGH Rockwell Automation CVE published 2026-01-29

CVE-2025-9466

CVE-2025-9466 affects Rockwell Automation ArmorStart LT and can cause a denial-of-service condition. According to the CISA CSAF advisory published on 2026-01-29, execution of Achilles EtherNet/IP and CIP grammar tests may trigger an unexpected device reboot, taking the Link State Monitor down for several seconds. Rockwell Automation reported no patch or upgrade available at publication and recommended app [truncated]

HIGH Rockwell Automation CVE published 2026-01-29

CVE-2025-9465

CVE-2025-9465 is a high-severity availability issue affecting Rockwell Automation ArmorStart LT products. CISA’s republication of Rockwell Automation advisory SD1768 states that, during execution of Achilles Comprehensive grammar tests, the device can reboot unexpectedly and cause the Link State Monitor to go down for several seconds. Rockwell’s guidance at the time was mitigation-focused: there was no pa [truncated]

HIGH Rockwell Automation CVE published 2026-01-29

CVE-2025-9464

CVE-2025-9464 is a denial-of-service issue affecting Rockwell Automation ArmorStart LT. According to the CISA advisory, fuzzing multiple CIP classes can make the CIP port unresponsive. The advisory was published on 2026-01-29 and states that no patch or upgrade was available at that time; Rockwell advised applying security best practices to reduce risk.

HIGH Rockwell Automation CVE published 2026-01-29

CVE-2025-9283

CVE-2025-9283 describes an availability issue in Rockwell Automation ArmorStart LT. Per the CISA-republished advisory, the device can reboot unexpectedly during Achilles EtherNet/IP Step Limits Storms tests, which causes the Link State Monitor to go down for several seconds. The advisory states that no patch or upgrade is available at the time of publication, and recommends applying security best practice [truncated]

HIGH Rockwell Automation CVE published 2026-01-29

CVE-2025-9282

CVE-2025-9282 affects Rockwell Automation ArmorStart LT devices and is described as a denial-of-service issue. In the CISA republished advisory, the device can reboot unexpectedly during Achilles Comprehensive limited storm tests, causing the Link State Monitor to go down for several seconds. Rockwell Automation reported no patch or upgrade at the time of the advisory and recommended applying ICS security [truncated]

HIGH Rockwell Automation CVE published 2026-01-29

CVE-2025-9281

CVE-2025-9281 is a denial-of-service issue in Rockwell Automation ArmorStart LT. CISA’s 2026-01-29 advisory says the device can reboot unexpectedly during Achilles Comprehensive step limit storm tests, which causes the Link State Monitor to go down for several seconds. The advisory lists ArmorStart LT 290D, 291D, and 294D as affected and states that no patch or upgrade was available at publication, so ope [truncated]

HIGH Rockwell Automation CVE published 2026-01-29

CVE-2025-9280

CVE-2025-9280 describes a denial-of-service condition in Rockwell Automation ArmorStart LT. According to the advisory summary, fuzzing with Defensics can make the device unresponsive and require a reboot. Rockwell states that no patch or upgrade is available at this time and recommends compensating security best practices.

HIGH Rockwell Automation CVE published 2026-01-29

CVE-2025-9279

CVE-2025-9279 is a denial-of-service issue affecting Rockwell Automation ArmorStart LT products. In the CISA-republished advisory, the device can reboot unexpectedly during Achilles EtherNet/IP Step Limit Storm testing, which drops the Link State Monitor for several seconds. CISA’s source material lists no patch or upgrade at the time of publication and recommends applying security best practices as a mitigation.

HIGH Rockwell Automation CVE published 2026-01-29

CVE-2025-9278

CVE-2025-9278 is a denial-of-service issue in Rockwell Automation ArmorStart LT. According to the advisory text, running a Burp Suite active scan can cause the device to lose ICMP connectivity, which then makes the web application inaccessible. CISA republished the vendor advisory on 2026-01-29 as ICSA-26-029-02.

HIGH Rockwell Automation CVE published 2026-01-29

CVE-2025-14027

CVE-2025-14027 covers multiple denial-of-service weaknesses in Rockwell Automation ControlLogix Redundancy Enhanced Modules 1756-RM2 and 1756-RM2XT firmware. According to the CISA CSAF advisory, crafted inputs such as malformed Class 3 messages, memory leak conditions, and other resource-exhaustion scenarios can cause the device to become unresponsive and, in some cases, trigger a major nonrecoverable fau [truncated]

MEDIUM Rockwell Automation CVE published 2026-01-22

CVE-2025-11743

Rockwell Automation CompactLogix 5370 has a denial-of-service vulnerability that can be triggered by a malformed CIP forward open message. According to the CISA advisory, the condition can cause a major nonrecoverable fault and require a restart to recover. Rockwell provides fixed versions for affected branches, and CISA also points readers to Rockwell security guidance for systems that cannot be upgraded [truncated]

HIGH Rockwell Automation CVE published 2026-01-20

CVE-2025-14377

CVE-2025-14377 is a high-severity information exposure issue in Rockwell Automation Verve Asset Manager’s legacy Ansible playbook component. According to the CISA republication of the vendor advisory, sensitive information could be incorrectly stored in unencrypted form during playbook execution. Rockwell Automation states the issue was resolved in version 1.42, and that the legacy component became option [truncated]

HIGH Rockwell Automation CVE published 2026-01-20

CVE-2025-14376

CVE-2025-14376 was publicly disclosed on 2026-01-20 in CISA's republished advisory for Rockwell Automation Verve Asset Manager. The issue affects the legacy ADI server component, where unencrypted sensitive data was stored in environment variables. Rockwell Automation states the issue was resolved in version 1.42, and that the component became optional beginning with version 1.36 in 2024, which means expo [truncated]

HIGH Rockwell Automation CVE published 2026-01-13

CVE-2025-9368

Rockwell Automation’s 432ES-IG3 Series A is affected by a denial-of-service vulnerability in the GuardLink EtherNet/IP Interface. According to the CISA-republished advisory, the condition can disrupt availability and requires a manual power cycle to restore the device. Rockwell’s documented fix is to update to V2.001.9 or later.

HIGH Rockwell Automation CVE published 2026-01-13

CVE-2025-12807

CVE-2025-12807 is a high-severity issue in Rockwell Automation FactoryTalk DataMosaix Private Cloud. CISA’s advisory says low-privilege users can perform sensitive database operations through exposed API endpoints. The supplied CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) scores 8.8, so this should be treated as a serious exposure in environments running the affected product. The advisory’s revis [truncated]

HIGH Rockwell Automation CVE published 2025-12-18

CVE-2025-13824

A vulnerability in Rockwell Automation Micro800 series programmable logic controllers (PLCs) allows remote attackers to cause a denial-of-service condition by sending malformed Common Industrial Protocol (CIP) packets to affected devices. The vulnerability was identified during fuzzing activities and results in the controller entering a hard fault state with a solid red Fault LED, rendering the device unr [truncated]

MEDIUM Rockwell Automation CVE published 2025-12-18

CVE-2025-13823

A recoverable fault condition exists in the IPv6 stack of Rockwell Automation Micro850 and Micro870 programmable logic controllers. The vulnerability triggers when affected controllers receive multiple malformed IPv6 packets, as discovered during fuzzing activities. The fault is recoverable, indicating the controller can resume normal operation without permanent damage, but successful exploitation results [truncated]

HIGH Rockwell Automation CVE published 2025-11-13

CVE-2024-22019

Rockwell Automation FactoryTalk Policy Manager is affected by CVE-2024-22019, a network-reachable denial-of-service issue in Node.js HTTP server handling of chunked encoding. According to the CISA CSAF advisory, a specially crafted HTTP request can cause the server to read an unbounded number of bytes from a single connection via chunk extension processing, which can exhaust CPU and network bandwidth and [truncated]

HIGH Rockwell Automation CVE published 2025-10-14

CVE-2025-9177

CVE-2025-9177 is a denial-of-service issue in Rockwell Automation’s 1715 EtherNet/IP Comms Module. According to the CISA CSAF advisory, a high volume of requests can crash the module’s web server. The advisory states that I/O control and communication are not impacted, but the webpage is unavailable until the device is power-cycled.

CRITICAL Rockwell Automation CVE published 2025-07-31

CVE-2025-41236

CVE-2025-41236 is a critical integer-overflow vulnerability in VMware’s VMXNET3 virtual network adapter. CISA’s Rockwell Automation advisory maps the issue to multiple Rockwell Automation VMware-based product families and directs customers to Broadcom’s remediation guidance. The stated impact is code execution on the host.

CRITICAL Rockwell Automation CVE published 2025-05-22

CVE-2018-1285

CVE-2018-1285 is a critical XXE issue mapped by CISA to Rockwell Automation FactoryTalk Historian ThingWorx product 95057C-FTHTWXCT11. The advisory states that Apache log4net versions before 2.0.10 do not disable XML external entities when parsing configuration files, which can expose applications that accept attacker-controlled log4net configuration files to high-impact data exposure and manipulation risks.

HIGH Rockwell Automation CVE published 2025-04-29

CVE-2025-3618

CVE-2025-3618 is a high-severity denial-of-service vulnerability in Rockwell Automation ThinManager. According to CISA’s advisory, the software does not adequately verify the outcome of memory allocation while processing Type 18 messages, which can let an attacker cause a denial of service on the target software. Rockwell Automation states the issue is fixed in multiple ThinManager releases, including 11. [truncated]

HIGH Rockwell Automation CVE published 2025-04-10

CVE-2025-3289

CVE-2025-3289 is a high-severity local code execution vulnerability in Rockwell Automation Arena. According to CISA’s advisory, improper validation of user-supplied data can trigger a stack-based memory buffer overflow. If a legitimate user opens a malicious DOE file, an attacker could disclose information and execute arbitrary code on the system. CISA published the advisory on 2025-04-10 and later revise [truncated]

HIGH Rockwell Automation CVE published 2025-04-10

CVE-2025-3288

CVE-2025-3288 is a high-severity local code execution vulnerability in Rockwell Automation Arena. CISA’s advisory says the flaw stems from improper validation of user-supplied data, which can lead to reading outside the allocated memory buffer. If a legitimate user opens a malicious DOE file on an affected system, an attacker may be able to disclose information and execute arbitrary code.

HIGH Rockwell Automation CVE published 2025-04-10

CVE-2025-3287

CVE-2025-3287 is a high-severity local code execution vulnerability in Rockwell Automation Arena. According to the CISA advisory, a legitimate user must open a malicious DOE file, and improper validation of user-supplied data can lead to reading outside the allocated memory buffer. The reported impact includes information disclosure and arbitrary code execution on the system. Rockwell Automation advises u [truncated]

HIGH Rockwell Automation CVE published 2025-04-10

CVE-2025-3286

CVE-2025-3286 is a high-severity local code execution issue in Rockwell Automation Arena. CISA’s advisory says the flaw stems from improper validation of user-supplied data and an out-of-bounds memory read, and that exploitation can disclose information and execute arbitrary code if a legitimate user opens a malicious DOE file. Rockwell Automation’s mitigation is to upgrade to V16.20.09 or later.

HIGH Rockwell Automation CVE published 2025-04-10

CVE-2025-3285

CVE-2025-3285 affects Rockwell Automation Arena and is rated CVSS 7.8 (High). CISA’s advisory describes a local code execution flaw caused by improper validation of user-supplied data, allowing a read outside the allocated memory buffer. In practical terms, a legitimate user must open a malicious DOE file for the issue to be triggered, and successful exploitation could disclose information and execute arb [truncated]

HIGH Rockwell Automation CVE published 2025-04-10

CVE-2025-2829

CVE-2025-2829 is a high-severity flaw in Rockwell Automation Arena that can let an attacker disclose information and execute arbitrary code on a system. According to CISA’s advisory, the issue affects Arena version 16.20.08 and earlier, and exploitation requires a legitimate user to open a malicious DOE file. Rockwell Automation recommends upgrading to V16.20.09 or later.