Rockwell Automation Logix Controllers Buffer Overflow Denial-of-Service Vulnerabilities
First seen Jul 18, 2026 · Updated Jul 18, 2026 · CVSS 8.6
Three vulnerabilities (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) affect multiple Rockwell Automation Logix controller families, allowing an unauthenticated remote attacker to send an invalid project or malformed file data that triggers a classic buffer overflow, causing the device to enter a major non-recoverable fault (MNRF). Exploitation results in denial-of-service impacting industrial control processes rather than data confidentiality or integrity loss. No known public exploitation has been reported to CISA at this time.
Technical Analysis
The vulnerabilities stem from CWE-120 (Buffer Copy without Checking Size of Input) in the controller firmware and boot firmware of CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix product lines. CVE-2025-12011 affects 5370/5570 controllers via loading of an invalid project file, while CVE-2025-12012 and CVE-2025-11698 affect 5380/5480/5580 controllers and their boot firmware through writing invalid file data, all leading to an MNRF condition requiring manual recovery. CVSS v3.1 scores 8.6 (High) with network attack vector, low complexity, no privileges or user interaction required, and CVSS v4.0 scores 9.2 (Critical), reflecting the ease of remote exploitation against internet-exposed or inadequately segmented OT networks. These are availability-impact only vulnerabilities (no confidentiality/integrity loss per the CVSS vector) affecting operational technology hardware, not AI agent software stacks; however, organizations running AI-driven industrial automation, predictive maintenance agents, or autonomous OT monitoring/control agents that interface with these Logix controllers could experience agent task failures, broken control loops, or unsafe fallback behavior if the underlying PLC enters a fault state, making this agent-relevant for AI systems tasked with real-time industrial process control or monitoring.
Affected Systems
Rockwell Automation CompactLogix 5370 <=V35.015; Compact GuardLogix 5370 <=V35.015; ControlLogix 5570 <=V35.015; GuardLogix 5570 <=V35.015; CompactLogix 5380 <=V34.012 and <=V35.011; Compact GuardLogix 5380 <=V34.012 and <=V35.011; CompactLogix 5480 <=V34.012 and <=V35.011; ControlLogix 5580 <=V34.012 and <=V35.011; GuardLogix 5580 <=V34.012 and <=V35.011; Recovery Images (CompactLogix 5380, Compact GuardLogix 5380, CompactLogix 5480, ControlLogix 5580, GuardLogix 5580) <=1.072.
Indicators of Compromise
- None published — this is a vendor-disclosed vulnerability advisory, not an active exploitation campaign. No hashes, IPs, or domains associated.
Remediation Steps
- 1
Update controller firmware
Update CompactLogix 5370, Compact GuardLogix 5370, ControlLogix 5570, and GuardLogix 5570 to V35.016, V36.011 or later; update CompactLogix 5380/5480, Compact GuardLogix 5380, ControlLogix 5580, and GuardLogix 5580 to V34.014, V35.013, V36.011 or later.
- 2
Update boot/recovery firmware
Update recovery images to boot firmware version 1.072 or greater; note that devices already running V36.013, V37.011 or later already include the corrected boot firmware.
- 3
Network segmentation
Isolate control system networks and devices behind firewalls, separate from business IT networks, and ensure no direct internet accessibility.
- 4
Secure remote access
Use up-to-date VPNs for any required remote access to ICS devices, recognizing VPN security depends on the security of connected endpoints.
- 5
Monitoring and incident reporting
Perform risk assessments before deploying defensive measures, monitor for anomalous device fault conditions, and report suspected malicious activity to CISA.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.