CVE-2025-12011
Awaiting Analysis Awaiting Analysis - Queue

Denial-of-Service in Rockwell Automation 5370/5570 Controllers

Vulnerability report for CVE-2025-12011, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-14

Assigner: Rockwell Automation

Description

A denial-of-service issue exists in  5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter a major non-recoverable fault (MNRF).

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-14
Generated
2026-08-04
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
rockwell_automation compactlogix to 35.016 (inc)
rockwell_automation controllogix to 35.016 (inc)
rockwell_automation compact_guardlogix to 35.016 (inc)
rockwell_automation guardlogix to 35.016 (inc)
rockwell_automation compactlogix to 36.011 (inc)
rockwell_automation controllogix to 36.011 (inc)
rockwell_automation compact_guardlogix to 36.011 (inc)
rockwell_automation guardlogix to 36.011 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-120 The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2025-12011 is a high-severity vulnerability affecting Rockwell Automation's CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controllers in the 5370 and 5570 families. The issue is a buffer overflow vulnerability that allows a remote attacker to load an invalid project onto the device.

When exploited, this vulnerability causes the device to enter a major non-recoverable fault (MNRF), which disrupts its normal operation. The vulnerability is classified under CWE-120 (Classic Buffer Overflow).

  • Affected devices include CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controllers.
  • The vulnerability has a CVSS 3.1 score of 8.6 and a CVSS 4.0 score of 9.2, indicating significant risk.
  • No known exploit exists at this time.
Detection Guidance

Detecting this vulnerability on your network or system involves checking the firmware versions of your Rockwell Automation controllers and monitoring for unusual project loading activities.

  • Identify affected devices: Verify if you have Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix, or GuardLogix controllers from the 5370 or 5570 families.
  • Check firmware versions: Use Rockwell Automation's Studio 5000 or FactoryTalk software to inspect the firmware version of your controllers. The vulnerability affects devices running firmware versions prior to V35.016 or V36.011.
  • Monitor network traffic: Use network monitoring tools to detect unusual project uploads or unexpected communication attempts to the controllers. Look for abnormal project files being loaded onto the devices.
  • Review logs: Check controller logs for any instances of major non-recoverable faults (MNRF) or unexpected reboots, which may indicate exploitation attempts.

Specific commands or tools for detection are not provided in the context, but Rockwell Automation's official tools like Studio 5000 or FactoryTalk can be used to verify firmware versions and inspect device logs.

Impact Analysis

This vulnerability can have serious operational and security impacts if exploited.

  • A remote attacker could cause a denial-of-service (DoS) condition by loading an invalid project, leading to a major non-recoverable fault (MNRF) in the affected controllers.
  • This disruption could halt industrial processes or operations that rely on these controllers, potentially causing downtime, financial losses, or safety risks.
  • Since the fault is non-recoverable, manual intervention may be required to restore normal device functionality.
Compliance Impact

The impact of this vulnerability on compliance with standards and regulations depends on the industry and the specific use of the affected devices.

  • For industries subject to GDPR (General Data Protection Regulation), this vulnerability may not directly relate to personal data protection. However, if the affected controllers are part of a system that processes or stores personal data, a disruption could lead to availability issues, which may indirectly affect compliance.
  • For organizations subject to HIPAA (Health Insurance Portability and Accountability Act), if the affected controllers are used in healthcare systems (e.g., managing medical devices or patient data systems), a disruption could impact the availability and integrity of critical systems. This may lead to non-compliance if it affects the confidentiality, integrity, or availability of protected health information (PHI).
  • In industrial environments, standards like IEC 62443 (industrial cybersecurity) may be relevant. This vulnerability could violate requirements for system availability, integrity, and resilience, potentially leading to non-compliance if not mitigated.
  • Organizations may also face compliance risks under sector-specific regulations (e.g., NERC CIP for energy, NIST SP 800-53 for federal systems) if the vulnerability is not addressed in a timely manner.
Mitigation Strategies

To mitigate this vulnerability, follow these immediate steps:

  • Upgrade firmware: Apply the latest firmware updates provided by Rockwell Automation. The vulnerability is corrected in firmware versions V35.016, V36.011, and later.
  • Isolate affected devices: If immediate firmware upgrades are not possible, isolate the affected controllers from untrusted networks to prevent remote exploitation.
  • Restrict access: Limit network access to the controllers to only trusted users and systems. Use firewalls or network segmentation to reduce exposure.
  • Monitor for attacks: Continuously monitor the controllers for signs of exploitation, such as unexpected project loads or MNRF events.

No workaround is available for this vulnerability, so upgrading the firmware is the primary mitigation step.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-12011. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart