Description
A denial-of-service issue exists in  5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter a major non-recoverable fault (MNRF).
Published: 2026-07-14
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A buffer overflow flaw permits a remote user to load a malformed project file into a CompactLogix 5370, Compact GuardLogix 5370, ControlLogix 5570, or GuardLogix 5570 controller, causing the device to enter a major non‑recoverable fault and terminating all operations. The resulting denial of service requires a manual reset or firmware re‑installation. The weakness is the classic CWE‑120 buffer overflow.

Affected Systems

Rockwell Automation CompactLogix 5370, Compact GuardLogix 5370, ControlLogix 5570, and GuardLogix 5570 controllers are affected.

Risk and Exploitability

The CVSS score of 9.2 indicates critical severity. The EPSS score of <1% suggests a low probability of public exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote client sending a crafted project file over the controller’s network interface.

Generated by OpenCVE AI on July 31, 2026 at 10:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update or patch released by Rockwell Automation for the affected CompactLogix 5370, Compact GuardLogix 5370, ControlLogix 5570, and GuardLogix 5570 controllers.
  • Block or restrict the controller’s management network interface using firewall rules or network segmentation, preventing external devices from transmitting project files.
  • If a vendor patch is not yet available, disable the project‑load feature or configure the controller to allow project loading only from trusted internal sources.

Generated by OpenCVE AI on July 31, 2026 at 10:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation compact Guardlogix 5370
Rockwellautomation compactlogix 5370
Rockwellautomation controllogix 5570
Rockwellautomation guardlogix 5570
Vendors & Products Rockwellautomation
Rockwellautomation compact Guardlogix 5370
Rockwellautomation compactlogix 5370
Rockwellautomation controllogix 5570
Rockwellautomation guardlogix 5570

Tue, 14 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Description A denial-of-service issue exists in  5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter a major non-recoverable fault (MNRF).
Title CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow
Weaknesses CWE-120
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


Subscriptions

Rockwellautomation Compact Guardlogix 5370 Compactlogix 5370 Controllogix 5570 Guardlogix 5570
cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-07-14T15:26:29.661Z

Reserved: 2025-10-21T12:56:46.593Z

Link: CVE-2025-12011

cve-icon Vulnrichment

Updated: 2026-07-14T15:26:17.553Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:30:17Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')