Rockwell Automation GuardLogix and ControlLogix controllers Vulnerable to Denial-Of-Service Attack
Description
A malformed CIP request can cause a major non-recoverable fault (MNRF) and denial-of-service (DoS) in Rockwell Automation Logix controllers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A malformed CIP request can cause a major non-recoverable fault (MNRF) and denial-of-service (DoS) in Rockwell Automation Logix controllers.
Vulnerability
A vulnerability exists in certain Rockwell Automation Logix controllers where processing a malformed Common Industrial Protocol (CIP) request can trigger a major non-recoverable fault (MNRF). The affected products include multiple versions of ControlLogix, CompactLogix, and other Logix family controllers. An attacker can exploit this by sending a specially crafted CIP message to the controller without requiring authentication or prior knowledge of the system configuration [1].
Exploitation
An attacker with network access to the affected controller can send a malformed CIP request over the network. No authentication, session, or user interaction is required. The attack does not require any special privileges and can be carried out over Ethernet/IP connections commonly used in industrial control networks [1].
Impact
Successful exploitation causes a major non-recoverable fault (MNRF) on the controller, leading to a denial-of-service (DoS) condition. The controller may stop executing the control program, requiring manual intervention or power cycling to restore normal operation. This can result in unplanned downtime and potential safety risks in critical infrastructure environments [1].
Mitigation
Rockwell Automation has released a product notice (ID 1613) with details on affected controller firmware versions and recommended mitigations. Users should update their controller firmware to the versions specified in the advisory. As a workaround, network segmentation and access controls (e.g., firewall rules, VPNs) can be used to limit exposure to trusted networks only. The vendor advisory is available after logging in to the Rockwell Automation support portal [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
628+ 1 more
- (no CPE)range: 28
- (no CPE)range: 20
- Range: 20
- Range: 20
- Range: 20
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
0No linked articles in our index yet.