Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix
CSIRTS triage
- What
- Vulnerabilities could allow denial-of-service conditions in the affected products.
- Who is affected
- Users of the affected Rockwell Automation products with specified versions.
- Urgency
- Remediation is urgent due to the potential for service disruption.
- Action
- Users should update to versions later than V35.015 or V34.012.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix
Get an email when a new CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-06
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-120110.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2025-120120.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2025-116980.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-12011 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-12012 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-11698 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Rockwell Automation CompactLogix and ControlLogix: Multiple vulnerabilitiescert-bund
- unknownCVE-2025-11698: A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than versio…nvd
- unknownCVE-2025-12012: A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could poten…nvd
- unknownCVE-2025-12011: A denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentiall…nvd
Recent advisories for Rockwell Automation CompactLogix
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalRockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Modulecisa · 2026-07-30
- high[NEW] [high] Rockwell Automation CompactLogix and ControlLogix: Multiple vulnerabilitiescert-bund · 2026-07-17
More from CISA Cybersecurity Advisories
- criticalWatchfire Controller Software2026-07-30
- criticalMZ Automation GmbH libiec618502026-07-30
- criticalToptech Systems RCU II+ and Multiload II+2026-07-30
- criticalNASA Core Flight System (cFS) Health & Safety (HS) Application2026-07-30
- criticalMikroTik RouterOS2026-07-30