CVE-2026-9636
Awaiting Analysis Awaiting Analysis - Queue

CIP Security Certificate Bypass in CompactLogix 5380

Vulnerability report for CVE-2026-9636, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-14

Assigner: Rockwell Automation

Description

A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a Certificate Revocation List (CRL). This could allow a network-based attacker to establish a connection using a certificate that should be untrusted, potentially bypassing CIP Security protections.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-14
Generated
2026-08-03
AI Q&A
2026-07-14
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
rockwell_automation controllogix_5580 From 36 (inc) to 37 (inc)
rockwell_automation compactlogix_5380 From 36 (inc) to 37 (inc)
rockwell_automation guardlogix_5580 From 36 (inc) to 37 (inc)
rockwell_automation compact_guardlogix_5380 From 36 (inc) to 37 (inc)
rockwell_automation 1756-en4 From 6.001 (inc) to 8.001 (inc)
rockwell_automation 1756-en4tr From 6.001 (inc) to 7.001 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-299 The product does not check or incorrectly checks the revocation status of a certificate, which may cause it to use a certificate that has been compromised.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-9636 is a security vulnerability affecting Rockwell Automation's CompactLogix 5380, ControlLogix 5580, GuardLogix 5580, Compact GuardLogix 5380, and 1756-EN4 communication modules. The issue involves improper handling of Certificate Revocation Lists (CRLs). Specifically, the controller fails to properly reject certificates that are signed by an intermediate certificate that has been revoked via a CRL.

This flaw could allow a network-based attacker to establish a connection using a certificate that should be untrusted. By doing so, the attacker may bypass CIP Security protections, which are designed to ensure secure communication in industrial control systems.

  • Affected firmware versions include V36-V37 for ControlLogix and CompactLogix controllers and V6.001-V8.001 for the 1756-EN4TR module.
  • The vulnerability only impacts users who have enabled the CRL feature and are using intermediary certificates. Those who do not use this feature are not affected.
Detection Guidance

Detecting this vulnerability requires verifying whether your Rockwell Automation controllers or communication modules are using the CRL feature with intermediary certificates and whether they are running affected firmware versions.

  • Check the firmware version of your ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, Compact GuardLogix 5380, or 1756-EN4/EN4TR modules. The vulnerability affects firmware versions V36-V37 for controllers and V6.001-V8.001 for the 1756-EN4TR module.
  • Verify if the CRL feature is enabled on your devices. This vulnerability only impacts systems where the CRL feature is active and intermediary certificates are in use.
  • Use Rockwell Automation's Studio 5000 or other supported configuration tools to inspect the certificate configuration and CRL settings. Look for signs of revoked intermediate certificates that may not be properly rejected.
  • Monitor network traffic for unexpected CIP Security connections. An attacker exploiting this vulnerability may establish connections using certificates that should be rejected due to revocation.

Specific commands or tools for detection are not provided in the context, but you may refer to Rockwell Automation's documentation or support for guidance on checking firmware versions and CRL configurations.

Impact Analysis

If you are using the affected Rockwell Automation devices with the CRL feature enabled and intermediary certificates, this vulnerability could have several impacts.

  • A network-based attacker could bypass CIP Security protections, allowing them to establish unauthorized connections to your industrial control systems.
  • This could lead to unauthorized access, manipulation, or disruption of critical industrial processes, potentially causing operational downtime or safety risks.
  • The attacker might exploit this flaw to gain a foothold in your network, which could be used for further attacks or data exfiltration.

The vulnerability is rated with a CVSS 4.0 base score of 8.2, indicating a significant risk, particularly in environments where secure communication is critical.

Compliance Impact

This vulnerability could impact compliance with several common standards and regulations, depending on the industry and the specific use of the affected devices.

  • GDPR: If the affected systems process or store personal data of EU citizens, a breach resulting from this vulnerability could lead to unauthorized access or exposure of personal data. This may violate GDPR requirements for data protection and could result in significant fines or legal consequences.
  • HIPAA: For organizations in the healthcare sector, if the affected systems handle protected health information (PHI), this vulnerability could lead to unauthorized access to PHI. This would violate HIPAA's Security Rule, which requires safeguards to protect the confidentiality, integrity, and availability of PHI.
  • Industrial Standards (e.g., IEC 62443, NIST SP 800-82): The vulnerability undermines the security controls required by industrial cybersecurity standards. Failure to address this issue could result in non-compliance with these standards, which are often mandated for critical infrastructure sectors.

Organizations using the affected devices should assess their compliance obligations and take corrective actions, such as applying the provided firmware updates, to mitigate risks and maintain compliance.

Mitigation Strategies

To mitigate this vulnerability, follow these immediate steps:

  • Upgrade the firmware of affected devices to the corrected versions. For ControlLogix and CompactLogix controllers, upgrade to firmware version V38.011 or later. For the 1756-EN4TR module, upgrade to firmware version V7.001 or later.
  • If upgrading is not immediately possible, disable the CRL feature if it is not critical to your operations. This will prevent the vulnerability from being exploited, though it may reduce security controls.
  • Ensure that all intermediary certificates used in your environment are valid and not revoked. Remove or replace any revoked certificates to prevent potential exploitation.
  • Monitor network traffic for unauthorized or suspicious CIP Security connections. Implement network segmentation to limit access to vulnerable devices.
  • Refer to Rockwell Automation's security advisory (SD1788) for additional guidance and updates on the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9636. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart