Description
A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF).
Published: 2026-07-14
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer overflow in the boot firmware of Rockwell Automation controllers 5380, 5480, and 5580 allows a malicious user to write invalid data, causing the device to enter a major non-recoverable fault. This leads to a denial of service, rendering the controller unusable until physically reset or repaired. The weakness is identified as CWE-120 and affects the availability of the device.

Affected Systems

The affected hardware includes Rockwell Automation CompactLogix 5380 Recovery Image, Compact GuardLogix 5380 Recovery Image, Compact Logix 5480 Recovery Image, Control Logix 5580 Recovery Image, and Guard Logix 5580 Recovery Image. Firmware versions earlier than 1.072 are vulnerable; controllers running 1.072 or newer are not affected. No other version or product information is supplied.

Risk and Exploitability

The CVSS score of 9.2 denotes high severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack would require an adversary capable of providing corrupted firmware or file data to the controller, which typically implies local or privileged access to the update interface. No public exploit is known, so the risk is mainly due to potential internal threat actors or attackers who gain physical or privileged network access.

Generated by OpenCVE AI on July 31, 2026 at 10:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update firmware to version 1.072 or newer on all affected Rockwell Automation controllers.
  • Restrict the ability to load firmware or files to authorized personnel only, ensuring that firmware updates cannot be performed by unauthorized users.
  • Validate the integrity and structure of firmware files before loading them into the controller to prevent malformed data from triggering the buffer overflow.

Generated by OpenCVE AI on July 31, 2026 at 10:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation compact Guardlogix 5380 Recovery Image
Rockwellautomation compactlogix 5380 Recovery Image
Rockwellautomation compactlogix 5480 Recovery Image
Rockwellautomation controllogix 5580 Recovery Image
Rockwellautomation guardlogix 5580 Recovery Image
Vendors & Products Rockwellautomation
Rockwellautomation compact Guardlogix 5380 Recovery Image
Rockwellautomation compactlogix 5380 Recovery Image
Rockwellautomation compactlogix 5480 Recovery Image
Rockwellautomation controllogix 5580 Recovery Image
Rockwellautomation guardlogix 5580 Recovery Image

Tue, 14 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF).
Title CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow
Weaknesses CWE-120
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


Subscriptions

Rockwellautomation Compact Guardlogix 5380 Recovery Image Compactlogix 5380 Recovery Image Compactlogix 5480 Recovery Image Controllogix 5580 Recovery Image Guardlogix 5580 Recovery Image
cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-07-14T15:53:19.355Z

Reserved: 2025-10-13T16:23:13.209Z

Link: CVE-2025-11698

cve-icon Vulnrichment

Updated: 2026-07-14T15:53:16.327Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:30:17Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')