CVE-2025-11694
Awaiting Analysis Awaiting Analysis - Queue
Denial-of-Service in Rockwell Automation 1769 CompactLogix Controllers

Publication date: 2026-06-16

Last updated on: 2026-06-16

Assigner: Rockwell Automation

Description
A security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and source IP addresses in the CIP protocol. This allows attacker to abuse the exposed Connection ID’s visible on the web interface to perform denial-of-service attacks, resulting in a minor fault.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-16
Last Modified
2026-06-16
Generated
2026-06-16
AI Q&A
2026-06-16
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
rockwell_automation compactlogix_5370_l1 to V38.011 (inc)
rockwell_automation compactlogix_5370_l2 to V38.011 (inc)
rockwell_automation compactlogix_5370_l3 to V38.011 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-354 The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability affects Rockwell Automation's CompactLogix 5370 controllers, specifically versions V36 and V38.011. It is caused by missing validation of sequence numbers and source IP addresses in the CIP protocol.

Attackers can exploit exposed Connection IDs visible on the web interface to perform denial-of-service (DoS) attacks, which result in minor faults in the affected controllers.

The issue is classified under CWE-354, which relates to improper validation of integrity check values.

Impact Analysis

The vulnerability allows attackers to perform denial-of-service attacks on affected CompactLogix 5370 controllers by abusing exposed Connection IDs.

These attacks cause minor faults in the controllers, potentially disrupting their normal operation.

Mitigation Strategies

To mitigate this vulnerability, update the firmware of affected Rockwell Automation CompactLogix 5370 controllers to version V38.011 or later, where the issue has been corrected.

Ensure that only trusted users have access to the web interface to reduce the risk of attackers exploiting exposed Connection IDs.

Compliance Impact

The provided information does not specify any direct impact of this vulnerability on compliance with common standards and regulations such as GDPR or HIPAA.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-11694. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart