VYPR
advisoryPublished Jul 30, 2026· 1 source

Rockwell Automation ICS Modules Vulnerable to CIP Security Bypass

CISA warns of a vulnerability in Rockwell Automation's CompactLogix and ControlLogix industrial control system modules that could allow attackers to bypass security protections.

CISA has issued an advisory detailing a critical vulnerability affecting Rockwell Automation's CompactLogix 5380, ControlLogix 5580, and 1756-EN4TR communications modules. The vulnerability, identified as CVE-2026-9636, stems from an improper handling of certificate revocation within the CIP Security protocol.

Specifically, the affected controllers fail to properly reject certificates that have been signed by an intermediate certificate that has subsequently been revoked. This flaw could enable a network-based attacker to establish a connection using a certificate that should be considered untrusted. By exploiting this, an attacker could potentially bypass the security measures implemented by CIP Security, undermining the integrity and confidentiality of industrial control system communications.

The vulnerability impacts several product versions. For Rockwell Automation ControlLogix 5580, GuardLogix 5580, CompactLogix 5580, and Compact GuardLogix 5580, versions ranging from V36 up to and including V37 are affected. Additionally, the 1756-EN4TR communications module is vulnerable in versions V6.001 and V7.001.

While no known public exploitation has been reported to CISA at this time, the potential impact is significant. Successful exploitation could lead to a denial-of-service condition, disrupting critical industrial operations. The CVSS v3.1 score for this vulnerability is a medium 5.9, with a CVSS v4.0 score of 8.2 (High), highlighting the severity of the potential threat.

Rockwell Automation has provided specific remediation steps. Users are strongly advised to update their affected products to the latest recommended versions. For ControlLogix 5580, GuardLogix 5580, CompactLogix 5580, and Compact GuardLogix 5580, the recommended update is to V38.011. For the 1756-EN4TR communications module, the update to V8.001 is recommended.

CISA emphasizes the importance of defensive measures to minimize the risk of exploitation. These include minimizing network exposure for all control system devices, ensuring they are not accessible from the internet, and locating control system networks behind firewalls, isolating them from business networks. When remote access is necessary, secure methods like VPNs should be employed, ensuring they are kept updated.

This advisory underscores the ongoing challenges in securing industrial control systems (ICS), particularly concerning the proper implementation and handling of cryptographic protocols like CIP Security. Vulnerabilities that allow for the bypass of established security mechanisms can have far-reaching consequences in critical infrastructure environments where operational continuity is paramount.

Organizations are encouraged to review their configurations, apply the recommended vendor updates promptly, and implement robust network segmentation and access control policies to protect their ICS environments from potential threats. Staying informed about advisories from vendors and agencies like CISA is crucial for maintaining a strong security posture.

Synthesized by Vypr AI