A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF).
History

Mon, 27 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation compact Guardlogix 5380 Recovery Image
Rockwellautomation compactlogix 5380 Recovery Image
Rockwellautomation compactlogix 5480 Recovery Image
Rockwellautomation controllogix 5580 Recovery Image
Rockwellautomation guardlogix 5580 Recovery Image
Vendors & Products Rockwellautomation
Rockwellautomation compact Guardlogix 5380 Recovery Image
Rockwellautomation compactlogix 5380 Recovery Image
Rockwellautomation compactlogix 5480 Recovery Image
Rockwellautomation controllogix 5580 Recovery Image
Rockwellautomation guardlogix 5580 Recovery Image

Tue, 14 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF).
Title CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow
Weaknesses CWE-120
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published: 2026-07-14T15:05:32.682Z

Updated: 2026-07-14T15:53:19.355Z

Reserved: 2025-10-13T16:23:13.209Z

Link: CVE-2025-11698

cve-icon Vulnrichment

Updated: 2026-07-14T15:53:16.327Z

cve-icon NVD

No data.

cve-icon Redhat

No data.