A security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and source IP addresses in the CIP protocol. This allows attacker to abuse the exposed Connection ID’s visible on the web interface to perform denial-of-service attacks, resulting in a minor fault.
Metrics
Affected Vendors & Products
References
History
Tue, 16 Jun 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rockwellautomation
Rockwellautomation compactlogix 5370 |
|
| Vendors & Products |
Rockwellautomation
Rockwellautomation compactlogix 5370 |
Tue, 16 Jun 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 16 Jun 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and source IP addresses in the CIP protocol. This allows attacker to abuse the exposed Connection ID’s visible on the web interface to perform denial-of-service attacks, resulting in a minor fault. | |
| Title | Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities | |
| Weaknesses | CWE-354 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Rockwell
Published:
Updated: 2026-06-16T15:21:42.199Z
Reserved: 2025-10-13T15:55:35.637Z
Link: CVE-2025-11694
Updated: 2026-06-16T15:21:32.309Z
Status : Awaiting Analysis
Published: 2026-06-16T15:16:32.693
Modified: 2026-06-16T15:26:04.250
Link: CVE-2025-11694
No data.
OpenCVE Enrichment
Updated: 2026-06-16T16:30:16Z