Description
A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover
Published: 2026-09-01
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

Improper validation of input length during CIP message processing can cause a major nonrecoverable fault that requires a power cycle to recover, effectively rendering the system unavailable. The weakness is a classic buffer over-read (CWE-119) that can be triggered by malicious or malformed messages sent to the device.

Affected Systems

Rockwell Automation CompactLogix 5380 and ControlLogix 5580 running firmware versions v33, v34.011 through v34.014, v35.011 through v35.013, and v36.011 through v36.012 are vulnerable.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity. EPSS data is unavailable, but the absence of a KEV listing suggests it has not yet been widely exploited. An attacker can craft CIP messages of arbitrary length to trigger the fault; the attack vector is inferred to be remote over the CIP network interface, provided the device is exposed to a network that an attacker can reach.

Generated by OpenCVE AI on September 1, 2026 at 15:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑published firmware patch for CompactLogix 5380 or ControlLogix 5580 as soon as it is available.
  • If a patch cannot be applied immediately, restrict or block CIP traffic to the affected device to prevent malicious message delivery.
  • Maintain monitoring of the device’s operational status and segregate it from critical networks to limit the impact of any potential denial‑of‑service events.

Generated by OpenCVE AI on September 1, 2026 at 15:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover
Title CompactLogix® 5380 / ControlLogix® 5580 - Multiple Vulnerabilities
First Time appeared Rockwell Automation
Rockwell Automation compactlogix 5380 Controllogix 5580
Weaknesses CWE-119
CPEs cpe:2.3:a:rockwell_automation:compactlogix_5380_controllogix_5580:v33_and_prior_v34.011-v34.014_v35.011-v35.013_v36.011-v36.012:*:*:*:*:*:*:*
Vendors & Products Rockwell Automation
Rockwell Automation compactlogix 5380 Controllogix 5580
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Rockwell Automation Compactlogix 5380 Controllogix 5580
cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-09-01T15:44:01.789Z

Reserved: 2026-05-26T18:11:06.053Z

Link: CVE-2026-9637

cve-icon Vulnrichment

Updated: 2026-09-01T15:43:58.790Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T14:17:50.157

Modified: 2026-09-01T20:50:01.960

Link: CVE-2026-9637

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T16:00:12Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer