CVE-2025-11698: CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow
A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11698?
The severity of CVE-2025-11698 is critical with a score of 9.2.
How do I fix CVE-2025-11698?
To fix CVE-2025-11698, update the boot firmware on 5380/5480/5580 controllers to version 1.072 or higher.
What devices are affected by CVE-2025-11698?
CVE-2025-11698 affects Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controllers with boot firmware lower than version 1.072.
What type of vulnerability is CVE-2025-11698?
CVE-2025-11698 is classified as a buffer overflow vulnerability that can lead to a denial of service.
What could happen if CVE-2025-11698 is exploited?
Exploitation of CVE-2025-11698 could allow a malicious user to cause the controller to enter a major non-recoverable fault.