Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.2
CVE-2025-12012: Rockwell Automation Controllers Risk of Device Crash
CVE-2025-12012 · published 2 months ago
Summary
Some Rockwell Automation controllers can crash if a hacker sends them bad data, causing them to stop working. This is a concern because it could disrupt operations and potentially lead to equipment damage or other safety issues. To mitigate this risk, ensure your controllers are up to date with the latest security patches.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| rockwell automation | compactlogix® 5370 compact guardlogix® 5370 controllogix® 5570 guardlogix® 5570 | V34.012 and earlier V35.011 and earlier |
Original advisory text
CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow
A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF).
Severity
9.2
Critical
CVSS 4.0: 9.2 (NVD)
Exploitation
EPSS <1%
Type
CWE-120Classic Buffer Overflow
Timeline
Published14 Jul 2026
Updated25 Sep 2026
First seen14 Jul 2026
Track software like this
Free during beta