Impact
A flaw in CompactLogix® and ControlLogix® modules causes the controller to accept certificates signed by a revoked intermediate certificate, enabling a network attacker to authenticate with a certificate that should be disallowed. Because CIP Security relies on strict certificate validation, the vulnerability can lead to unintended access and potential control of the device.
Affected Systems
Rockwell Automation products affected include ControlLogix® 5580, CompactLogix® 5380, GuardLogix® 5580, Compact GuardLogix® 5380, and the 1756-EN4TR communications module. The vendor recommends upgrading firmware to version 38.011 or later for the first four products, and to version 8.001 or later specifically for the 1756-EN4TR module.
Risk and Exploitability
The CVSS score of 8.2 labels this a high‑severity issue, while the EPSS score indicates a very low probability of exploitation at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, suggesting it is not a current known exploit. A network‑based attacker who can present a carefully crafted certificate could bypass CIP Security protections, but would need network connectivity to the controller and knowledge of the certificate chain.
OpenCVE Enrichment