Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module
Summary
A security vulnerability has been identified in Rockwell Automation's CompactLogix 5380, ControlLogix 5580, and 1756-EN4TR Communications Modules. The vulnerability, CVE-2026-9636, allows a network-based attacker to bypass security protections by establishing a connection using a revoked certificate.
IFF Assessment
This vulnerability allows attackers to bypass security controls, which is detrimental to defenders.
Severity
The CVSS score of 5.9 (MEDIUM) reflects a vulnerability with an "Improper Check for Certificate Revocation" that could allow a network-based attacker to establish a connection using an untrusted certificate, potentially bypassing security protections.
Defender Context
This vulnerability in industrial control systems (ICS) requires immediate attention from defenders, particularly in critical manufacturing sectors. Organizations should verify the affected firmware versions and apply necessary updates or mitigation strategies to prevent unauthorized access and potential denial-of-service conditions.