Denial of Service Vulnerability in Rockwell Automation Products
CVE-2026-11317

8.7HIGH

What is CVE-2026-11317?

A denial of service issue arises within Rockwell Automation's Controllogix and Compactlogix systems, triggered by specially crafted CIP messages. This flaw is particularly problematic for devices with limited memory, as it can result in a significant nonrecoverable fault (MNRF). Recovering from this issue necessitates a program download, underscoring the critical need for vigilance and timely system updates to mitigate potential risks.

Affected Version(s)

CompactLogix, ControlLogix Versions prior to 34.016

CompactLogix, ControlLogix Versions prior to 34.016

CompactLogix, ControlLogix Versions prior to 35.015

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.