CVE-2026-9307 PUBLISHED

Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities

Assigner: Rockwell
Reserved: 22.05.2026 Published: 16.06.2026 Updated: 16.06.2026

A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct malicious packets, leading to Denial-of-Service.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.3

Product Status

Vendor Rockwell Automation
Product CompactLogix 5370
Versions Default: unaffected
  • Version V36 is affected

Solutions

V38.011 https://compatibility.rockwellautomation.com/Pages/MultiProductFindDownloads.aspx

References

Problem Types

  • CWE-497 Exposure of sensitive system information to an unauthorized control sphere CWE