Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2025-12011: Rockwell Automation Controllers Buffer Overflow Risk

CVE-2025-12011 · published 2 months ago
Summary

Certain Rockwell Automation controllers can be exploited by a remote user to cause a major failure. This could lead to downtime and lost productivity. To mitigate this risk, users should update their controllers to the latest software versions and follow recommended security best practices.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
rockwell automation compactlogix® 5370 compact guardlogix® 5370 controllogix® 5570 guardlogix® 5570 35.015 and earlier
Original advisory text
CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow
A denial-of-service issue exists in  5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter a major non-recoverable fault (MNRF).
Severity
9.2 Critical
CVSS 4.0: 9.2 (NVD)
Exploitation
EPSS <1%
Type
CWE-120Classic Buffer Overflow
Timeline
Published14 Jul 2026
Updated25 Sep 2026
First seen14 Jul 2026
Sources
CVE-2025-12011 · MITRE
Track software like this
Free during beta