Denial-of-Service Vulnerability in Logix Platforms by Rockwell Automation
CVE-2026-9637

8.7HIGH

What is CVE-2026-9637?

A significant vulnerability has been identified in Rockwell Automation's Logix platforms which arises from insufficient validation of input lengths during the processing of CIP messages. Exploitation of this weakness may lead to a nonrecoverable fault, necessitating a complete power cycle to restore normal operations. This could have serious implications for operational continuity and system stability, making it crucial for users to understand the potential risks and take appropriate action.

Affected Version(s)

CompactLogix® 5380 / ControlLogix® 5580 V33 and prior, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.