CVE-2025-12012: CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow
A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12012?
CVE-2025-12012 has a severity score of 9.2, categorized as critical.
What systems are affected by CVE-2025-12012?
CVE-2025-12012 affects Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controllers.
What type of vulnerability is CVE-2025-12012?
CVE-2025-12012 is a buffer overflow vulnerability that can lead to denial-of-service.
How do I fix CVE-2025-12012?
To mitigate CVE-2025-12012, ensure you apply the recommended patches from Rockwell Automation as soon as they are available.
What are the potential consequences of CVE-2025-12012?
Exploitation of CVE-2025-12012 could lead to a major non-recoverable fault in affected controllers, disrupting operations.