# Rockwell Logix controllers vulnerable to CIP DoS

Published: 2026-06-16 · Severity: medium · Sectors: manufacturing
Canonical: https://vorant.io/reports/06522341-e0a5-53a4-8d7b-4201536a0111/rockwell-logix-controllers-vulnerable-to-cip-dos

> A crafted CIP message can trigger a major nonrecoverable fault in Rockwell Automation CompactLogix and ControlLogix 5370/5570 controllers, requiring manual program download to recover.

CISA has published an advisory for CVE-2026-11317, a denial-of-service vulnerability affecting Rockwell Automation's Logix 5370 and 5570 controller families used in critical manufacturing environments worldwide. The vulnerability stems from improper resource handling when processing crafted Common Industrial Protocol (CIP) messages, causing affected devices to enter a major nonrecoverable fault (MNRF) state that requires a program download to restore operation. Controllers with lower memory capacity face heightened susceptibility.

Affected products include CompactLogix 5370 (versions ≤34.016), Compact GuardLogix 5370 (≤35.015), ControlLogix 5570 (≤35.015), and GuardLogix 5570 (version 36.012). Rockwell Automation has released firmware updates addressing the issue and recommends upgrading to CompactLogix 5370 v34.016+, Compact GuardLogix 5370 v35.015+, ControlLogix 5570 v36.012+, and GuardLogix 5570 v37.011+.

CISA emphasizes defense-in-depth strategies for industrial control systems, including network segmentation, firewall isolation from business networks, and restricting internet exposure. No active exploitation targeting this vulnerability has been reported to CISA at the time of publication. Organizations should assess operational impact before deploying patches to production environments.

## Mentioned in this report

- Vulnerabilities: CVE-2026-11317

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-03

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/06522341-e0a5-53a4-8d7b-4201536a0111/rockwell-logix-controllers-vulnerable-to-cip-dos.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
