CVE-2025-12011: CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow
Published Jul 14, 2026
·Updated
A denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter a major non-recoverable fault (MNRF).
Affected Software
4 affected components
Rockwell Automation CompactLogix controllers
Rockwell Automation ControlLogix controllers
Rockwell Automation Compact GuardLogix controllers
Rockwell Automation GuardLogix controllers
Event History
Jul 14, 2026
CVE Published
via MITRE·03:03 PM
Data Sourced
via MITRE·03:03 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-12011?
CVE-2025-12011 has a critical severity rating of 9.2.
2
What systems are affected by CVE-2025-12011?
CVE-2025-12011 affects Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controllers.
3
What type of vulnerability is CVE-2025-12011?
CVE-2025-12011 is a buffer overflow vulnerability that can lead to a denial-of-service condition.
4
How do I mitigate CVE-2025-12011?
To mitigate CVE-2025-12011, ensure that you do not load invalid projects on affected controllers.
5
What could happen if CVE-2025-12011 is exploited?
If exploited, CVE-2025-12011 could cause the device to enter a major non-recoverable fault, leading to possible service interruption.