Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2025-11694: 1769 CompactLogix Controllers: Denial-of-Service Risk Through Web Interface

CVE-2025-11694
Summary

Some 1769 CompactLogix controllers have a security issue that makes it possible for an attacker to shut down the system by sending fake messages. This can cause minor disruptions to the system. To stay safe, users should ensure their controllers are up to date with the latest security patches.

Original title
A security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and source IP addresses in the CIP protocol. This allows attacker to abuse the exposed...
Original description
A security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and source IP addresses in the CIP protocol. This allows attacker to abuse the exposed Connection ID’s visible on the web interface to perform denial-of-service attacks, resulting in a minor fault.
nvd CVSS4.0 8.7
Vulnerability type
CWE-354
Published: 16 Jun 2026 · Updated: 17 Jun 2026 · First seen: 16 Jun 2026