Description
A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a Certificate Revocation List (CRL). This could allow a network-based attacker to establish a connection using a certificate that should be untrusted, potentially bypassing CIP Security protections.
Published: 2026-07-14
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in CompactLogix® and ControlLogix® modules causes the controller to accept certificates signed by a revoked intermediate certificate, enabling a network attacker to authenticate with a certificate that should be disallowed. Because CIP Security relies on strict certificate validation, the vulnerability can lead to unintended access and potential control of the device.

Affected Systems

Rockwell Automation products affected include ControlLogix® 5580, CompactLogix® 5380, GuardLogix® 5580, Compact GuardLogix® 5380, and the 1756-EN4TR communications module. The vendor recommends upgrading firmware to version 38.011 or later for the first four products, and to version 8.001 or later specifically for the 1756-EN4TR module.

Risk and Exploitability

The CVSS score of 8.2 labels this a high‑severity issue, while the EPSS score indicates a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, suggesting it is not a current known exploit. A network‑based attacker who can present a carefully crafted certificate could bypass CIP Security protections, but would need network connectivity to the controller and knowledge of the certificate chain.

Generated by OpenCVE AI on July 31, 2026 at 10:13 UTC.

Remediation

Vendor Solution

Upgrade to firmware version 38.011 or later. For 1756-EN4TR upgrade to version 8.001 or later.


OpenCVE Recommended Actions

  • Upgrade the firmware on CompactLogix 5380 and ControlLogix 5580 devices to version 38.011 or later, and on GuardLogix products to the corresponding firmware update.
  • Upgrade the 1756-EN4TR communication module to firmware version 8.001 or newer.
  • Ensure that the devices are configured to retrieve and apply CRL updates automatically, and confirm that only non‑revoked certificates are trusted within the system.

Generated by OpenCVE AI on July 31, 2026 at 10:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a Certificate Revocation List (CRL). This could allow a network-based attacker to establish a connection using a certificate that should be untrusted, potentially bypassing CIP Security protections.
Title Rockwell Automation CompactLogix® 5380 ControlLogix® 5580 / 1756-EN4 Communications Module – Certificate Revocation List Vulnerability
Weaknesses CWE-299
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-07-14T15:55:05.004Z

Reserved: 2026-05-26T18:10:55.329Z

Link: CVE-2026-9636

cve-icon Vulnrichment

Updated: 2026-07-14T15:55:00.563Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:15:06Z

Weaknesses
  • CWE-299

    Improper Check for Certificate Revocation