CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2702

As cited

Copy frozen at (site build).

vulnerabilities

Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix

Rockwell Automation has disclosed three denial-of-service vulnerabilities (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) affecting multiple CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controller models with a CVSS score of 8.6. These flaws could allow a remote attacker to load an invalid project file, causing affected devices to enter a major non-recoverable fault. Rockwell recommends updating to patched versions such as V35.016, V36.011, or later depending on the controller model.

Why it matters: Organizations operating critical manufacturing infrastructure worldwide using these Rockwell Automation controllers are exposed to production downtime if systems are exploited; patching to the recommended versions is required to restore service availability and prevent operational disruptions.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix

Rockwell Automation has disclosed three denial-of-service vulnerabilities (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) affecting multiple CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controller models with a CVSS score of 8.6. These flaws could allow a remote attacker to load an invalid project file, causing affected devices to enter a major non-recoverable fault. Rockwell recommends updating to patched versions such as V35.016, V36.011, or later depending on the controller model.

Why it matters: Organizations operating critical manufacturing infrastructure worldwide using these Rockwell Automation controllers are exposed to production downtime if systems are exploited; patching to the recommended versions is required to restore service availability and prevent operational disruptions.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary