CVE-2026-9637
Received Received - Intake

Denial-of-Service in Rockwell Automation Logix Platforms Due to Improper CIP Message Input Validation

Vulnerability report for CVE-2026-9637, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Rockwell Automation

Description

A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
rockwell_automation logix *
rockwell_automation controllogix_5580 to 33 (exc)
rockwell_automation compactlogix_5380 to 33 (exc)
rockwell_automation guardlogix_5580 to 33 (exc)
rockwell_automation compact_guardlogix_5380 to 33 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-119 The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-9637 is a denial-of-service vulnerability affecting Rockwell Automation Logix platforms. It occurs due to improper input length validation during CIP message processing, which can cause a major nonrecoverable fault requiring a power cycle to restore functionality.

Detection Guidance

Monitor for unexpected major nonrecoverable faults (MNRF) in Logix platforms, particularly ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380. Check firmware versions for V33 and prior or specific ranges in V34-V37. Inspect CIP message processing logs for improper input validation attempts.

Impact Analysis

This vulnerability can cause system crashes, leading to operational downtime and potential loss of control over industrial processes. Affected systems include ControlLogix 5580, CompactLogix 5380, GuardLogix 5580, and Compact GuardLogix 5380 running vulnerable firmware versions.

Compliance Impact

This vulnerability could impact compliance with standards like GDPR and HIPAA by causing system outages due to denial-of-service conditions. Unplanned downtime may disrupt data processing or availability, which are critical requirements under these regulations. The need for power cycling to recover could lead to extended periods of non-compliance if systems are not restored promptly.

Mitigation Strategies

Upgrade affected Logix platforms to corrected firmware versions. If immediate upgrade is not possible, implement network segmentation to limit exposure and follow Rockwell Automation's security best practices for isolation and monitoring.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9637. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart