CVE-2026-9637 PUBLISHED

CompactLogix® 5380 / ControlLogix® 5580 - Multiple Vulnerabilities

Assigner: Rockwell
Reserved: 26.05.2026 Published: 01.09.2026 Updated: 01.09.2026

A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Rockwell Automation
Product CompactLogix® 5380 / ControlLogix® 5580
Versions Default: unaffected
  • Version V33 and prior, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 is affected

References

Problem Types

  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE