CVE-2025-11743: Rockwell Automation CompactLogix® 5370 Denial of Service Vulnerability
Published Jan 20, 2026
·Updated
A denial-of-service security issue in the affected product. The security issue occurs when a malformed CIP forward open message is sent. This could result in a major nonrecoverable fault a restart is required to recover.
Affected Software
1 affected component
Rockwell Automation CompactLogix 5370
Remediation
Information
Versions 37.011 and later, Version 34.016, Version 35.015, Version 36.012 https://compatibility.rockwellautomation.com/Pages/MultiProductFindDownloads.aspx
Event History
Jan 20, 2026
CVE Published
via MITRE·01:52 PM
Data Sourced
via MITRE·01:52 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-11743?
CVE-2025-11743 has a high severity rating due to its impact on system availability.
2
How do I fix CVE-2025-11743?
To mitigate CVE-2025-11743, ensure that your Rockwell Automation CompactLogix 5370 software is updated to the latest version addressing this vulnerability.
3
What products are affected by CVE-2025-11743?
CVE-2025-11743 affects the Rockwell Automation CompactLogix 5370 controllers.
4
What type of vulnerability is CVE-2025-11743?
CVE-2025-11743 is categorized as a denial-of-service vulnerability.
5
What could happen if CVE-2025-11743 is exploited?
Exploitation of CVE-2025-11743 can lead to a nonrecoverable fault requiring a restart of the affected system.