CVE-2025-9166: Rockwell Automation ControlLogix® 5580 V35.013 Denial-Of-Service
A denial-of-service security issue exists in the affected product and version. The security issue stems from the controller repeatedly attempting to forward messages. The issue could result in a major nonrecoverable fault on the controller.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rockwell Automation ControlLogix 5580to a version that resolves this vulnerability.Fixed in 35.014
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9166?
CVE-2025-9166 is classified as a high severity denial-of-service vulnerability.
How do I fix CVE-2025-9166?
To remediate CVE-2025-9166, update the affected Rockwell Automation ControlLogix 5580 software to the latest version.
What types of issues does CVE-2025-9166 cause?
CVE-2025-9166 can lead to a major nonrecoverable fault on the controller due to message forwarding attempts.
Which product is affected by CVE-2025-9166?
CVE-2025-9166 affects the Rockwell Automation ControlLogix 5580 product.
What does a denial-of-service vulnerability like CVE-2025-9166 mean?
A denial-of-service vulnerability like CVE-2025-9166 means that the system may become unresponsive or fail to operate normally.