As cited
Copy frozen at (site build).
vulnerabilities
Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix
Rockwell Automation has disclosed three denial-of-service vulnerabilities (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) affecting multiple CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controller models with a CVSS score of 8.6. These flaws could allow a remote attacker to load an invalid project file, causing affected devices to enter a major non-recoverable fault. Rockwell recommends updating to patched versions such as V35.016, V36.011, or later depending on the controller model.
Why it matters: Organizations operating critical manufacturing infrastructure worldwide using these Rockwell Automation controllers are exposed to production downtime if systems are exploited; patching to the recommended versions is required to restore service availability and prevent operational disruptions.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix
Rockwell Automation has disclosed three denial-of-service vulnerabilities (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) affecting multiple CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controller models with a CVSS score of 8.6. These flaws could allow a remote attacker to load an invalid project file, causing affected devices to enter a major non-recoverable fault. Rockwell recommends updating to patched versions such as V35.016, V36.011, or later depending on the controller model.
Why it matters: Organizations operating critical manufacturing infrastructure worldwide using these Rockwell Automation controllers are exposed to production downtime if systems are exploited; patching to the recommended versions is required to restore service availability and prevent operational disruptions.
- Source published
- First seen by Cybersecurity Tracker