Rockwell CompactLogix DoS flaws expose industrial controllers
Two vulnerabilities in Rockwell Automation CompactLogix 5370 controllers allow unauthenticated attackers to trigger denial-of-service via CIP protocol flaws.
CISA disclosed two vulnerabilities affecting Rockwell Automation CompactLogix 5370 L1, L2, and L3 controllers deployed worldwide in critical manufacturing environments. CVE-2025-11694 stems from missing validation of sequence numbers and source IP addresses in the Common Industrial Protocol (CIP), allowing attackers to abuse exposed Connection IDs to trigger minor faults and denial-of-service conditions. CVE-2026-9307 involves the controller's web server exposing CIP Connection IDs on diagnostics pages to unauthenticated users, providing attackers the information needed to craft malicious packets for DoS attacks.
Rockwell Automation has released firmware version V38.011 to remediate both vulnerabilities and published security advisory SD1776 with detailed mitigation guidance. CISA recommends organizations minimize network exposure for affected control systems, isolate them from business networks, and implement defense-in-depth strategies. No active exploitation targeting these vulnerabilities has been reported to CISA at this time.
The vulnerabilities affect a widely deployed industrial controller platform used in critical manufacturing sectors globally, creating potential operational disruption risk if exploited. Organizations operating affected CompactLogix controllers should prioritize patching and implement network segmentation controls per CISA guidance.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-04
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free