CVE-2025-12011
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition. The following versions of Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix are affected: CompactLogix 5370 <=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) Compact GuardLogix 5370 <=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) ControlLogix 5570 <=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) GuardLogix 5570 <=V35.015 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) CompactLogix 5380 <=V34.012 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) CompactLogix 5380 <=V35.011 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) Compact GuardLogix 5380 <=V34.012 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) Compact GuardLogix 5380 <=V35.011 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) CompactLogix 5480 <=V34.012 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) CompactLogix 5480 <=V35.011 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) ControlLogix 5580 <=V34.012 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) ControlLogix 5580 <=V35.011 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) GuardLogix 5580 <=V34.012 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) GuardLogix 5580 <=V35.011 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) CompactLogix 5380 Recovery Image <=1.072 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) Compact GuardLogix 5380 Recovery Image <=1.072 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) CompactLogix 5480 Recovery Image <=1.072 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) ControlLogix 5580 Recovery Image <=1.072 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) GuardLogix 5580 Recovery Image <=1.072 (CVE-2025-12011, CVE-2025-12012, CVE-2025-11698) CVSS Vendor Equipment Vulnerabilities v3 8.6 Rockwell Automation Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix Buffer Copy without Checking Size of Input ('Classic Buf
CSIRTS triage
- What
- Vulnerabilities could allow denial-of-service conditions in the affected products.
- Who is affected
- Users of the affected Rockwell Automation products with specified versions.
- Urgency
- Remediation is urgent due to the potential for service disruption.
- Action
- Users should update to versions later than V35.015 or V34.012.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2025-12011
Get an email if CVE-2025-12011 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
Advisory coverage (3)
- high[NEW] [high] Rockwell Automation CompactLogix and ControlLogix: Multiple vulnerabilitiescert-bund · 2026-07-17
- unknownRockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogixcisa · 2026-07-16
- unknownCVE-2025-12011: A denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentiall…nvd · 2026-07-14
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2025-12011)