Where
-Infinity
0
Severity
8.7
EPSS
0.04%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully unavailable and require a power cycle to recover.

Remedy

Affected Product      First Known in firmware Revision         Corrected in Firmware Revision         CompactLogix 5380 controllers         v33.011 <                     * v33.015 and later for versions 33     * v34.011 and later               Compact GuardLogix® 5380 controllers         v33.011<         CompactLogix 5480 controllers         v33.011<         ControlLogix 5580 controllers         v33.011<         GuardLogix 5580 controllers         v33.011<         1756-EN4TR         v3.002         * 4.001 and later     Mitigations and Workarounds Customers using the affected versions are encouraged to upgrade to corrected firmware versions. We also strongly encourage customers to implement our suggested security best practices to minimize the risk of the vulnerability. * Security Best Practices https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight
First published (updated )
Severity
8.6
EPSS
0.04%
Input Validation
AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will become unavailable and require a manual restart to recover it. Additionally, an MNRF could result in a loss of view and/or control of connected devices.

Remedy

Affected Product         First Known in Firmware Revision         Corrected in Firmware Revision         ControlLogix® 5580         V35.011         V35.013, V36.011         GuardLogix 5580         V35.011         V35.013, V36.011         CompactLogix 5380         V35.011         V35.013, V36.011         1756-EN4TR         V5.001         V6.001     Users using the affected software and who are not able to upgrade to one of the corrected versions are encouraged to apply security best practices, where possible.   * Security Best Practices https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight  
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203