CVE-2026-11317: Rockwell Automation Logix 5370 and 5570 Controllers Vulnerable To Denial of Service Via CIP
A denial of service security issue exists in the affected product. The security issue stems from a fault occurring when a crafted CIP message is sent. Devices with less memory are more likely to be affected. This can result in a major nonrecoverable fault (MNRF). A program download is required to recover.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rockwell Automation Logix 5370 and 5570 Controllersto a version that resolves this vulnerability.Fixed in 34.016 - Upgrade
Upgrade
Rockwell Automation Logix 5370 and 5570 Controllersto a version that resolves this vulnerability.Fixed in 35.015 - Upgrade
Upgrade
Rockwell Automation Logix 5370 and 5570 Controllersto a version that resolves this vulnerability.Fixed in 36.012 - Upgrade
Upgrade
Rockwell Automation Logix 5370 and 5570 Controllersto a version that resolves this vulnerability.Fixed in 37.011
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11317?
CVE-2026-11317 has a high severity rating of 8.7 according to the CVSS score.
How does CVE-2026-11317 affect Rockwell Automation controllers?
CVE-2026-11317 can lead to a denial of service due to a fault triggered by a specially crafted CIP message.
What types of devices are primarily impacted by CVE-2026-11317?
Devices with less memory are more likely to be affected by CVE-2026-11317.
What is the required action to recover from the effects of CVE-2026-11317?
To recover from the denial of service caused by CVE-2026-11317, a program download is necessary.
When was CVE-2026-11317 published?
CVE-2026-11317 was published on June 16, 2026.