Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2025-12012: Rockwell Automation Controllers Risk of Device Crash

CVE-2025-12012 · published 2 months ago
Summary

Some Rockwell Automation controllers can crash if a hacker sends them bad data, causing them to stop working. This is a concern because it could disrupt operations and potentially lead to equipment damage or other safety issues. To mitigate this risk, ensure your controllers are up to date with the latest security patches.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
rockwell automation compactlogix® 5370 compact guardlogix® 5370 controllogix® 5570 guardlogix® 5570 V34.012 and earlier V35.011 and earlier
Original advisory text
CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow
A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF).
Severity
9.2 Critical
CVSS 4.0: 9.2 (NVD)
Exploitation
EPSS <1%
Type
CWE-120Classic Buffer Overflow
Timeline
Published14 Jul 2026
Updated25 Sep 2026
First seen14 Jul 2026
Sources
CVE-2025-12012 · MITRE
Track software like this
Free during beta