CVE-2026-9307: Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities
A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct malicious packets, leading to Denial-of-Service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch V38.011 - Compensating control
Restrict network access to the CompactLogix controller web server/diagnostics webpage so only authenticated/trusted clients can reach it (prevent unauthenticated users on the network from accessing diagnostics and exposed CIP Connection IDs).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9307?
The severity of CVE-2026-9307 is rated as medium with a CVSS score of 6.3.
What does CVE-2026-9307 affect?
CVE-2026-9307 affects Rockwell Automation CompactLogix 5370 controllers, specifically related to sensitive information disclosure.
How do I fix CVE-2026-9307?
To mitigate CVE-2026-9307, ensure that access to the CompactLogix controllers is restricted to authenticated users only.
What kind of information is disclosed in CVE-2026-9307?
CVE-2026-9307 discloses CIP Connection IDs through the diagnostics webpage of the affected controllers.
Can CVE-2026-9307 be exploited by unauthenticated users?
Yes, CVE-2026-9307 can be exploited by any unauthenticated user on the network.