A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard fault with solid red Fault LED and becomes unresponsive. Upon power cycle, the controller will enter recoverable fault where the MS LED and Fault LED become flashing red and reports fault code 0xF019. To recover, clear the fault.
Advisories

No advisories yet.

Fixes

Solution

V23.012 https://compatibility.rockwellautomation.com/Pages/MultiProductFindDownloads.aspx ,  Migrate to the newer Micro850/870 controllers (L50E/L70E V23.012 https://compatibility.rockwellautomation.com/Pages/MultiProductFindDownloads.aspx ) ,  Migrate to the newer Micro820 controllers (L20E V23.011)


Workaround

No workaround given by the vendor.

History

Mon, 15 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 15 Dec 2025 15:30:00 +0000

Type Values Removed Values Added
Description A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard fault with solid red Fault LED and becomes unresponsive. Upon power cycle, the controller will enter recoverable fault where the MS LED and Fault LED become flashing red and reports fault code 0xF019. To recover, clear the fault.
Title Micro820®, Micro850®, Micro870® – Specialized Fuzzing Vulnerabilities
Weaknesses CWE-763
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2025-12-15T17:09:43.346Z

Reserved: 2025-12-01T14:29:33.649Z

Link: CVE-2025-13824

cve-icon Vulnrichment

Updated: 2025-12-15T16:36:09.352Z

cve-icon NVD

Status : Received

Published: 2025-12-15T16:15:50.197

Modified: 2025-12-15T16:15:50.197

Link: CVE-2025-13824

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses