CVE-2026-12659: Rockwell Automation Flex 5000® Adapter - Denial of Service
A denial-of-service security issue exists in the affected products. The security issue stems from improper handling of exceptional conditions when processing crafted CIP packets sent to the adapter. A power cycle is required to recover the module and associated I/O.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rockwell Automation Flex 5000 Adapterto a version that resolves this vulnerability.Fixed in 6.012 - Operational
Perform a power cycle to recover the module and associated I/O after applying the upgrade.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12659?
CVE-2026-12659 has a high severity rating of 8.7 according to the CVSS scoring system.
How do I fix CVE-2026-12659?
To address CVE-2026-12659, a power cycle of the affected Rockwell Automation Flex 5000 Adapter module is required to recover from the denial-of-service condition.
What is the impact of CVE-2026-12659?
CVE-2026-12659 can lead to a denial-of-service situation that requires manual intervention to restore functionality.
What causes the issue identified in CVE-2026-12659?
The issue in CVE-2026-12659 stems from improper handling of exceptional conditions when processing specially crafted CIP packets.
Which product is affected by CVE-2026-12659?
The affected product for CVE-2026-12659 is the Rockwell Automation Flex 5000 Adapter.