Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module

Summary

A security vulnerability has been identified in Rockwell Automation's CompactLogix 5380, ControlLogix 5580, and 1756-EN4TR Communications Modules. The vulnerability, CVE-2026-9636, allows a network-based attacker to bypass security protections by establishing a connection using a revoked certificate.

IFF Assessment

FOE

This vulnerability allows attackers to bypass security controls, which is detrimental to defenders.

Severity

5.9 Medium

The CVSS score of 5.9 (MEDIUM) reflects a vulnerability with an "Improper Check for Certificate Revocation" that could allow a network-based attacker to establish a connection using an untrusted certificate, potentially bypassing security protections.

Defender Context

This vulnerability in industrial control systems (ICS) requires immediate attention from defenders, particularly in critical manufacturing sectors. Organizations should verify the affected firmware versions and apply necessary updates or mitigation strategies to prevent unauthorized access and potential denial-of-service conditions.

Read Full Story →