Denial of Service Vulnerability in Rockwell Automation Products
CVE-2026-11317
8.7HIGH
Key Information:
- Vendor
Rockwell Automation
- Vendor
- CVE Published:
- 16 June 2026
What is CVE-2026-11317?
A denial of service issue arises within Rockwell Automation's Controllogix and Compactlogix systems, triggered by specially crafted CIP messages. This flaw is particularly problematic for devices with limited memory, as it can result in a significant nonrecoverable fault (MNRF). Recovering from this issue necessitates a program download, underscoring the critical need for vigilance and timely system updates to mitigate potential risks.
Affected Version(s)
CompactLogix, ControlLogix Versions prior to 34.016
CompactLogix, ControlLogix Versions prior to 34.016
CompactLogix, ControlLogix Versions prior to 35.015