CISA flags three Rockwell Automation controller denial-of-service flaws
For plants running Logix hardware, the operational risk is availability: invalid project or file data can trigger a major nonrecoverable fault.
TL;DR
CISA published ICSA-26-197-06 for CVE-2025-12011, CVE-2025-12012 and CVE-2025-11698, three Rockwell Automation CompactLogix, ControlLogix, GuardLogix and Compact GuardLogix buffer-overflow vulnerabilities. The advisory assigns CVSS v3.1 8.6 and covers critical manufacturing deployments worldwide. Defense primes, subs and other contractors running affected Rockwell controllers should check firmware levels, because exploitation can involve invalid project or file data and push a controller into a major nonrecoverable fault.
CISA's advisory gives operational technology owners a version-check job. It covers Rockwell Automation CompactLogix 5370 through V35.015, Compact GuardLogix 5370 through V35.015, ControlLogix and GuardLogix 5570 through V35.015, and 5380, 5480 and 5580 lines through the listed V34.012 or V35.011 branches, plus recovery images at or below 1.072. The vulnerabilities are tracked as CVE-2025-12011, CVE-2025-12012 and CVE-2025-11698 and mapped to CWE-120, classic buffer overflow. CISA says successful exploitation could cause denial of service; the advisory's CVE text describes invalid project loads or invalid file data causing a major nonrecoverable fault. For defense-industrial-base organizations with Rockwell gear in manufacturing, test, or facility control environments, the useful next step is inventory, then firmware planning against Rockwell's update targets. The advisory lists fixes, but it does not set an update deadline.
Published ·Deep Fathom