Executive Summary
In 2025, Rockwell Automation identified multiple vulnerabilities in its CompactLogix, ControlLogix, Compact GuardLogix, and GuardLogix controllers. These flaws, including CVE-2025-12011, CVE-2025-12012, and CVE-2025-11698, could allow remote attackers to cause major non-recoverable faults (MNRF) in affected devices, leading to denial-of-service conditions. The vulnerabilities were found in firmware versions up to V35.015 for certain models, with Rockwell Automation releasing patches in versions V35.016, V36.011, and later to address these issues. (rockwellautomation.com)
The discovery of these vulnerabilities underscores the critical importance of securing industrial control systems (ICS) against remote attacks. As ICS environments become increasingly interconnected, the potential impact of such vulnerabilities grows, highlighting the need for continuous monitoring, timely patching, and adherence to cybersecurity best practices to protect critical infrastructure.
Why This Matters Now
The identification of these vulnerabilities in Rockwell Automation's controllers highlights the ongoing risks in industrial control systems. Immediate attention is required to apply the recommended firmware updates to prevent potential exploitation, which could lead to significant operational disruptions in critical manufacturing sectors.
Attack Path Analysis
An attacker exploits a buffer overflow vulnerability in Rockwell Automation controllers to cause a denial-of-service condition, leading to a major non-recoverable fault (MNRF).
Kill Chain Progression
Initial Compromise
Description
The attacker remotely exploits a buffer overflow vulnerability in the controller's firmware by sending specially crafted packets.
Related CVEs
CVE-2025-12011
CVSS 9.2A denial-of-service vulnerability in Rockwell Automation 5370/5570 controllers allows a remote user to load an invalid project, causing the device to enter a major non-recoverable fault (MNRF).
Affected Products:
Rockwell Automation CompactLogix 5370 – <= V35.015
Rockwell Automation Compact GuardLogix 5370 – <= V35.015
Rockwell Automation ControlLogix 5570 – <= V35.015
Rockwell Automation GuardLogix 5570 – <= V35.015
Exploit Status:
no public exploitCVE-2025-12012
CVSS 9.2A denial-of-service vulnerability in Rockwell Automation 5380/5480/5580 controllers allows a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF).
Affected Products:
Rockwell Automation CompactLogix 5380 – <= V34.012, <= V35.011
Rockwell Automation Compact GuardLogix 5380 – <= V34.012, <= V35.011
Rockwell Automation CompactLogix 5480 – <= V34.012, <= V35.011
Rockwell Automation ControlLogix 5580 – <= V34.012, <= V35.011
Rockwell Automation GuardLogix 5580 – <= V34.012, <= V35.011
Exploit Status:
no public exploitCVE-2025-11698
CVSS 9.2A denial-of-service vulnerability in Rockwell Automation 5380/5480/5580 controllers with boot firmware versions lower than 1.072 allows a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF).
Affected Products:
Rockwell Automation CompactLogix 5380 Recovery Image – <= 1.072
Rockwell Automation Compact GuardLogix 5380 Recovery Image – <= 1.072
Rockwell Automation CompactLogix 5480 Recovery Image – <= 1.072
Rockwell Automation ControlLogix 5580 Recovery Image – <= 1.072
Rockwell Automation GuardLogix 5580 Recovery Image – <= 1.072
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Denial of Control
Denial of Service
Loss of Control
Endpoint Denial of Service
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NIST SP 800-53 – Denial of Service Protection
Control ID: SC-5
NIST SP 800-53 – Flaw Remediation
Control ID: SI-2
NIST SP 800-53 – Least Functionality
Control ID: CM-7
NIST SP 800-53 – Vulnerability Scanning
Control ID: RA-5
NIST SP 800-53 – Malicious Code Protection
Control ID: SI-3
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Industrial Automation
Critical Manufacturing sectors face severe operational disruption from Rockwell Automation PLC vulnerabilities enabling remote denial-of-service attacks on CompactLogix and ControlLogix systems.
Oil/Energy/Solar/Greentech
Energy infrastructure dependent on Rockwell automation controllers vulnerable to buffer overflow exploits causing major non-recoverable faults and potential production shutdowns.
Automotive
Manufacturing operations using affected Rockwell GuardLogix safety systems at risk of malicious project loading attacks disrupting assembly lines and safety controls.
Utilities
Power grid and water treatment facilities utilizing vulnerable ControlLogix platforms exposed to remote attacks causing critical infrastructure availability impacts.
Sources
- Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogixhttps://www.cisa.gov/news-events/ics-advisories/icsa-26-197-06Verified
- Rockwell Automation Security Advisory SD1781https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1781.htmlVerified
- NVD - CVE-2025-12011https://nvd.nist.gov/vuln/detail/CVE-2025-12011Verified
- NVD - CVE-2025-12012https://nvd.nist.gov/vuln/detail/CVE-2025-12012Verified
- NVD - CVE-2025-11698https://nvd.nist.gov/vuln/detail/CVE-2025-11698Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could likely limit the attacker's ability to exploit vulnerabilities, move laterally, and exfiltrate data within the cloud environment.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit the buffer overflow vulnerability may be constrained, reducing the likelihood of initial compromise.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges may be constrained, reducing the scope of unauthorized access.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the network may be constrained, reducing the potential spread of the attack.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish and maintain command channels may be constrained, reducing persistent control over compromised assets.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate data may be constrained, reducing the risk of data loss.
The attacker's ability to cause widespread denial-of-service conditions may be constrained, reducing the overall impact on the system.
Impact at a Glance
Affected Business Functions
- Industrial Control Systems Operations
- Manufacturing Processes
Estimated downtime: 3 days
Estimated loss: $50,000
n/a
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict unauthorized access to critical controllers.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation of known vulnerabilities.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to suspicious activities.
- • Apply Secure Hybrid Connectivity (DCE) to ensure secure communication channels between controllers.
- • Regularly update controller firmware to mitigate known vulnerabilities.



