CVE-2026-11317 PUBLISHED

Rockwell Automation Logix 5370 and 5570 Controllers Vulnerable To Denial of Service Via CIP

Assigner: Rockwell
Reserved: 04.06.2026 Published: 16.06.2026 Updated: 16.06.2026

A denial of service security issue exists in the affected product. The security issue stems from a fault occurring when a crafted CIP message is sent. Devices with less memory are more likely to be affected. This can result in a major nonrecoverable fault (MNRF). A program download is required to recover.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Rockwell Automation
Product CompactLogix, ControlLogix
Versions Default: affected
  • Version Versions prior to 34.016 is affected
  • Version Versions prior to 35.015 is affected
  • Version Versions prior to 36.012 is affected

Solutions

Upgrade to  Version 34.016 and laterVersion 35.015 and later Version 36.012 and later

Version 37.011 and later

References

Problem Types

  • CWE-404: Improper Resource Shutdown or Release CWE