rootpwn

Vulnerabilities

Rockwell Automation Logix Platforms Hit by CVE-2026-9637 Denial‑of‑Service Exploit

A critical denial‑of‑service flaw (CVE‑2026‑9637) has been uncovered in Rockwell Automation’s Logix family of controllers. The bug stems from improper input‑length validation in CIP message handling, allowing an attacker to trigger a non‑recoverable fault that forces a power cycle. The issue spans ControlLogix, CompactLogix, GuardLogix and Compact GuardLogix models up to firmware V36.012, with a CVSS score of 7.5. Rockwell recommends flashing the latest firmware (V37.011 for ControlLogix, V34.015 for CompactLogix, V37.011 for GuardLogix, V34.015 for Compact GuardLogix) to mitigate the risk.

Industrial control systems are no longer immune to classic denial‑of‑service attacks. A new vulnerability, CVE‑2026‑9637, has been identified in Rockwell Automation’s Logix platform family. The flaw lies in the Common Industrial Protocol (CIP) message parser, which fails to correctly validate the length of incoming data. An attacker can exploit this oversight to send malformed packets that crash the controller, forcing a hard reset and causing a major non‑recoverable fault (MNRF).

Affected Products

  • ControlLogix 5580 – firmware versions V33 and earlier, V34.011–V34.014, V35.011–V35.013, V36.011–V36.012
  • CompactLogix 5380 – firmware versions V33 and earlier, V34.011–V34.014, V35.011–V35.013, V36.011–V36.012
  • GuardLogix 5580 – firmware versions V33 and earlier, V34.011–V34.014, V35.011–V35.013, V36.011–V36.012
  • Compact GuardLogix 5380 – firmware versions V33 and earlier, V34.011–V34.014, V35.011–V35.013, V36.011–V36.012

Impact

The vulnerability can be leveraged to bring an entire control system down, disrupting production lines and potentially compromising safety. The CVSS score of 7.5 reflects the severity of the denial‑of‑service potential and the difficulty of mitigating without a firmware update.

Remediation

Rockwell Automation advises all impacted units to upgrade to the latest firmware releases:
  • ControlLogix: V37.011
  • CompactLogix: V34.015
  • GuardLogix: V37.011
  • Compact GuardLogix: V34.015

Updating firmware is the only effective countermeasure. Operators should verify that the new firmware version is correctly installed and that CIP message handling behaves as expected.

Next Steps for Operators

  • Audit all Logix controllers to confirm firmware versions.
  • Schedule firmware upgrades during planned maintenance windows.
  • Validate post‑upgrade stability through CIP traffic monitoring.
  • Implement network segmentation to limit potential attack vectors.

CVE-2026-9637 Rockwell Automation Denial of Service ControlLogix Industrial Control Systems

← All news