Description
A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent to the adapter. A power cycle is required to recover the module and associated I/O.
Published: 2026-07-14
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a denial‑of‑service issue in Rockwell Automation’s FLEX 5000 EtherNet/IP Adapter stemming from improper handling of exceptional conditions when the device processes specially crafted CIP packets. The fault can crash the adapter and requires a power cycle to recover. The crash results in a loss of availability for all I/O functions provided by the adapter.

Affected Systems

Rockwell Automation’s FLEX 5000 EtherNet/IP Adapter is affected. Firmware versions earlier than 6.012 contain the flaw. All installations that have not yet upgraded remain vulnerable.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. An EPSS score of less than one percent shows a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers could send specially crafted CIP packets over the network to trigger the failure, so the attack vector is likely remote network access without special privileges.

Generated by OpenCVE AI on August 4, 2026 at 18:37 UTC.

Remediation

Vendor Solution

Upgrade to version 6.012 or later.


OpenCVE Recommended Actions

  • Upgrade the FLEX 5000 EtherNet/IP Adapter firmware to version 6.012 or later, as released by Rockwell Automation.
  • Implement network segmentation or firewall rules to restrict unauthorized access to the adapter, limiting exposure to crafted CIP packets.
  • If a firmware upgrade cannot be performed immediately, isolate the adapter from the production network until the patch is applied to prevent potential denial‑of‑service attacks.

Generated by OpenCVE AI on August 4, 2026 at 18:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent to the adapter. A power cycle is required to recover the module and associated I/O.
Title Rockwell Automation Flex 5000® Adapter - Denial of Service
Weaknesses CWE-415
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-07-14T15:57:22.367Z

Reserved: 2026-06-18T18:54:20.493Z

Link: CVE-2026-12659

cve-icon Vulnrichment

Updated: 2026-07-14T15:57:17.683Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-14T16:16:45.170

Modified: 2026-07-14T16:46:49.030

Link: CVE-2026-12659

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T18:45:12Z

Weaknesses