CVE-2025-11743
Unknown Unknown - Not Provided
Denial of Service in Rockwell Automation CIP Forward Open Message

Publication date: 2026-01-20

Last updated on: 2026-01-20

Assigner: Rockwell Automation

Description
A denial-of-service security issue in the affected product. The security issue occurs when a malformed CIP forward open message is sent. This could result in a major nonrecoverable fault a restart is required to recover.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-01-20
Last Modified
2026-01-20
Generated
2026-05-07
AI Q&A
2026-01-20
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
rockwell_automation compactlogix_5370_controllers to 35.012 (exc)
rockwell_automation compactlogix_5370_controllers to 36.011 (exc)
rockwell_automation compactlogix_5370_controllers to 37.011 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is a denial-of-service (DoS) issue in Rockwell Automation's CompactLogix 5370 Controllers. It occurs when a malformed CIP (Common Industrial Protocol) forward open message is sent to the controller, causing a major nonrecoverable fault that forces the system to restart to recover. It is classified under CWE-1284: Improper Validation of Specified Quantity in Input. [1]


How can this vulnerability impact me? :

The impact of this vulnerability is a denial-of-service condition on affected CompactLogix 5370 Controllers. When exploited, it causes a major nonrecoverable fault requiring a system restart, which can lead to downtime and disruption of industrial control processes. [1]


What immediate steps should I take to mitigate this vulnerability?

To mitigate this vulnerability immediately, you should upgrade your Rockwell Automation CompactLogix 5370 Controllers to the corrected software versions: 37.011 or later, 34.016 or later, 35.015 or later, and 36.012 or later. If you are unable to upgrade immediately, follow Rockwell Automation's security best practices as recommended. There is no workaround available for this issue other than upgrading the software. [1]


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart