CVE-2026-9637
8.7Rockwell Automation · CompactLogix 5380 / ControlLogix 5580
A denial of service vulnerability in Rockwell Automation Logix controllers allows unauthenticated attackers to cause a major nonrecoverable fault via malformed CIP messages.
Executive summary
A critical denial of service vulnerability in Rockwell Automation Logix controllers permits unauthenticated remote attackers to crash systems, requiring a manual power cycle for recovery.
Vulnerability
The flaw is caused by improper validation of input length during CIP message processing (CWE-119). This vulnerability is remotely exploitable by an unauthenticated attacker, as indicated by the CVSS vector AV:N/AC:L/AT:N/PR:N/UI:N.
Business impact
The ability to trigger a major nonrecoverable fault in industrial control systems poses a severe risk to operational continuity. Because the device requires a physical power cycle to recover, a successful exploit could result in significant production downtime and operational disruption. The CVSS score of 8.7 reflects the high impact on system availability, which is critical in industrial environments.
Remediation
Immediate Action: Review the official Rockwell Automation security advisory (SD1792) to identify specific firmware updates or configuration changes required for your specific hardware revision.
Proactive Monitoring: Monitor industrial network traffic for anomalous CIP message patterns or spikes in traffic directed at Logix controller communication ports.
Compensating Controls: Implement strict network segmentation and firewall rules to restrict access to industrial communication protocols to authorized engineering workstations only.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for complete operational disruption, organizations using the affected Logix platforms must prioritize this advisory. Administrators should transition to the latest vendor-provided firmware as soon as testing permits to eliminate the underlying memory buffer vulnerability. In the interim, ensure that all affected controllers are isolated from untrusted networks to prevent remote exploitation.