CVE-2025-11698
Awaiting Analysis Awaiting Analysis - Queue

Denial-of-Service in Rockwell Automation 5380/5480/5580 Controllers

Vulnerability report for CVE-2025-11698, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-14

Assigner: Rockwell Automation

Description

A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-14
Generated
2026-08-03
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 11 associated CPEs
Vendor Product Version / Range
rockwell_automation 5380 1.072
rockwell_automation 5480 1.072
rockwell_automation 5580 1.072
rockwell_automation compactlogix *
rockwell_automation controllogix *
rockwell_automation compact_guardlogix *
rockwell_automation guardlogix *
rockwell_automation 5370 *
rockwell_automation 5570 *
rockwell_automation firmware 35.016
rockwell_automation firmware 36.011

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-120 The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2025-11698 is a denial-of-service vulnerability affecting Rockwell Automation's 5380, 5480, and 5580 controllers with boot firmware versions lower than 1.072. A malicious user can exploit this flaw by writing invalid file data to the controller.

This action causes the device to enter a major non-recoverable fault (MNRF), which disrupts its normal operation and may require physical intervention to restore functionality.

Detection Guidance

Detecting this vulnerability on your network or system involves checking the firmware version of the affected Rockwell Automation controllers. The vulnerability exists in 5380, 5480, and 5580 controllers with boot firmware versions lower than 1.072.

  • Identify the affected devices: Verify if your network includes Rockwell Automation 5380, 5480, or 5580 controllers, as well as CompactLogix, ControlLogix, Compact GuardLogix, or GuardLogix controllers.
  • Check firmware versions: Access the controller's configuration or use Rockwell Automation's software tools (e.g., Studio 5000 or FactoryTalk) to determine the boot firmware version. Compare it against the vulnerable version (lower than 1.072).
  • Monitor for unusual activity: Look for signs of a major non-recoverable fault (MNRF) on the controllers, such as unexpected reboots or loss of functionality. This may indicate exploitation attempts or the presence of the vulnerability.

Rockwell Automation does not provide specific commands for detection, but you can use their official tools to inspect firmware versions. Refer to their documentation for detailed steps.

Impact Analysis

If you are using an affected Rockwell Automation controller (5380, 5480, or 5580) with boot firmware lower than version 1.072, this vulnerability could impact you in the following ways:

  • Operational disruption: A successful exploit could cause the controller to enter a major non-recoverable fault (MNRF), halting industrial processes or automation tasks.
  • Downtime: Recovery from an MNRF may require manual intervention, leading to extended downtime and potential financial losses.
  • Security risk: The vulnerability could be exploited by unauthorized users to disrupt critical infrastructure, especially if the controller is accessible over a network.
Compliance Impact

The impact of CVE-2025-11698 on compliance with standards and regulations depends on the industry and use case of the affected controllers:

  • GDPR: If the affected controllers process or store personal data of EU citizens, a denial-of-service attack leading to downtime or data loss could violate GDPR's requirements for data availability and integrity. Organizations may face penalties if they fail to implement adequate security measures to protect against such vulnerabilities.
  • HIPAA: For healthcare organizations, if the controllers are part of systems handling protected health information (PHI), an exploit could disrupt access to critical medical systems. This may violate HIPAA's Security Rule, which mandates safeguards for electronic PHI (ePHI) availability and integrity.
  • Industrial standards: Compliance frameworks like NIST SP 800-82 (Guide to Industrial Control System Security) or IEC 62443 require organizations to protect industrial control systems (ICS) from vulnerabilities that could disrupt operations. Failure to patch or mitigate this vulnerability may result in non-compliance with these standards.

To maintain compliance, organizations should follow Rockwell Automation's recommendation to upgrade to the latest firmware version (1.072 or higher) and implement additional security controls to protect against unauthorized access.

Mitigation Strategies

To mitigate this vulnerability, follow these immediate steps:

  • Upgrade the boot firmware: Apply the latest firmware update (version 1.072 or higher) to all affected 5380, 5480, and 5580 controllers. This is the primary mitigation method as it resolves the underlying issue.
  • Isolate vulnerable devices: If upgrading is not immediately possible, isolate the affected controllers from untrusted networks to reduce the risk of exploitation.
  • Monitor for MNRF events: Set up alerts or logging to detect major non-recoverable faults, which may indicate an attack or exploitation attempt.
  • Review network access: Restrict access to the controllers to only authorized personnel and systems. Use firewalls or network segmentation to limit exposure.

Rockwell Automation recommends upgrading to the latest firmware as the most effective mitigation. No workaround is available for this vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-11698. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart