Rockwell Automation Logix Platform

Summary

Rockwell Automation's Logix Platform, including ControlLogix, CompactLogix, GuardLogix, and Compact GuardLogix, has a denial-of-service vulnerability (CVE-2026-9637). The flaw stems from improper validation of input length during CIP message processing, which can lead to a major nonrecoverable fault requiring a power cycle.

IFF Assessment

FOE

This vulnerability allows for a denial-of-service attack on critical industrial control systems, which is detrimental to defenders.

Severity

7.5 High

The CVSS score of 7.5 reflects a high severity, indicating that the vulnerability can cause a significant denial of service that requires a power cycle to recover, impacting the availability of critical infrastructure.

Defender Context

This vulnerability in Rockwell Automation's Logix Platform poses a significant risk to critical manufacturing infrastructure. Defenders should prioritize patching affected systems and monitor for any attempts to exploit this denial-of-service flaw. The impact of a major nonrecoverable fault on industrial operations necessitates prompt attention.

Read Full Story →