CVE-2025-11694 PUBLISHED

Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities

Assigner: Rockwell
Reserved: 13.10.2025 Published: 16.06.2026 Updated: 16.06.2026

A security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and source IP addresses in the CIP protocol. This allows attacker to abuse the exposed Connection ID’s visible on the web interface to perform denial-of-service attacks, resulting in a minor fault.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Rockwell Automation
Product CompactLogix 5370
Versions Default: unaffected
  • Version V36 is affected

Solutions

V38.011 https://compatibility.rockwellautomation.com/Pages/MultiProductFindDownloads.aspx

References

Problem Types

  • CWE-354 Improper validation of integrity check value CWE