highOther

Rockwell Automation Logix Controllers Buffer Overflow Denial-of-Service Vulnerabilities

First seen Jul 18, 2026 · Updated Jul 18, 2026 · CVSS 8.6

ICSOTdenial-of-servicebuffer-overflowrockwell-automationcritical-manufacturingfirmwarePLC

Three vulnerabilities (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) affect multiple Rockwell Automation Logix controller families, allowing an unauthenticated remote attacker to send an invalid project or malformed file data that triggers a classic buffer overflow, causing the device to enter a major non-recoverable fault (MNRF). Exploitation results in denial-of-service impacting industrial control processes rather than data confidentiality or integrity loss. No known public exploitation has been reported to CISA at this time.

Technical Analysis

The vulnerabilities stem from CWE-120 (Buffer Copy without Checking Size of Input) in the controller firmware and boot firmware of CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix product lines. CVE-2025-12011 affects 5370/5570 controllers via loading of an invalid project file, while CVE-2025-12012 and CVE-2025-11698 affect 5380/5480/5580 controllers and their boot firmware through writing invalid file data, all leading to an MNRF condition requiring manual recovery. CVSS v3.1 scores 8.6 (High) with network attack vector, low complexity, no privileges or user interaction required, and CVSS v4.0 scores 9.2 (Critical), reflecting the ease of remote exploitation against internet-exposed or inadequately segmented OT networks. These are availability-impact only vulnerabilities (no confidentiality/integrity loss per the CVSS vector) affecting operational technology hardware, not AI agent software stacks; however, organizations running AI-driven industrial automation, predictive maintenance agents, or autonomous OT monitoring/control agents that interface with these Logix controllers could experience agent task failures, broken control loops, or unsafe fallback behavior if the underlying PLC enters a fault state, making this agent-relevant for AI systems tasked with real-time industrial process control or monitoring.

Affected Systems

Rockwell Automation CompactLogix 5370 <=V35.015; Compact GuardLogix 5370 <=V35.015; ControlLogix 5570 <=V35.015; GuardLogix 5570 <=V35.015; CompactLogix 5380 <=V34.012 and <=V35.011; Compact GuardLogix 5380 <=V34.012 and <=V35.011; CompactLogix 5480 <=V34.012 and <=V35.011; ControlLogix 5580 <=V34.012 and <=V35.011; GuardLogix 5580 <=V34.012 and <=V35.011; Recovery Images (CompactLogix 5380, Compact GuardLogix 5380, CompactLogix 5480, ControlLogix 5580, GuardLogix 5580) <=1.072.

Indicators of Compromise

  • None published — this is a vendor-disclosed vulnerability advisory, not an active exploitation campaign. No hashes, IPs, or domains associated.

Remediation Steps

  1. 1

    Update controller firmware

    Update CompactLogix 5370, Compact GuardLogix 5370, ControlLogix 5570, and GuardLogix 5570 to V35.016, V36.011 or later; update CompactLogix 5380/5480, Compact GuardLogix 5380, ControlLogix 5580, and GuardLogix 5580 to V34.014, V35.013, V36.011 or later.

  2. 2

    Update boot/recovery firmware

    Update recovery images to boot firmware version 1.072 or greater; note that devices already running V36.013, V37.011 or later already include the corrected boot firmware.

  3. 3

    Network segmentation

    Isolate control system networks and devices behind firewalls, separate from business IT networks, and ensure no direct internet accessibility.

  4. 4

    Secure remote access

    Use up-to-date VPNs for any required remote access to ICS devices, recognizing VPN security depends on the security of connected endpoints.

  5. 5

    Monitoring and incident reporting

    Perform risk assessments before deploying defensive measures, monitor for anomalous device fault conditions, and report suspected malicious activity to CISA.

CVE / Advisory IDs

CVE-2025-12011CVE-2025-12012CVE-2025-11698

Industries Most Exposed

Critical ManufacturingIndustrial AutomationEnergyWater/WastewaterChemical

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.