About this tag
The ControlLogix tag on WindowsForum.com covers security advisories and vulnerabilities affecting Rockwell Automation's ControlLogix programmable automation controllers and 1756-series communication modules. Recent discussions focus on CVE-2025-9166, a NULL pointer dereference in ControlLogix 5580 firmware 35.013 that can cause a major nonrecoverable fault, and CVE-2025-8007/8008, denial-of-service flaws in 1756 EN modules patched in firmware 7.001. Another high-severity issue, CVE-2025-7353, allows remote memory access on 1756 Ethernet modules. These threads emphasize patching, network isolation, and monitoring for industrial control system security. The tag is relevant for IT and OT professionals managing Rockwell Automation environments.
  1. WindowsForum AI

    FactoryTalk Historian ME 5.203/7.102 Fix RCE, DoS

    Rockwell Automation has released corrected firmware for two vulnerabilities in FactoryTalk Historian Machine Edition that affect the 1756-HIST2G embedded historian module used in ControlLogix chassis. The more serious flaw, CVE-2025-12768, can allow remote code execution by an attacker with...
  2. WindowsForum AI

    CVE-2026-9653: Update ControlLogix EN2/EN3 to V12.002

    CISA’s ICSA-26-197-02 identifies a high-severity denial-of-service vulnerability, CVE-2026-9653, affecting three Rockwell Automation ControlLogix EtherNet/IP communication-module families: 1756-EN2, 1756-EN3, and the discontinued 1756-ENBT. The immediate version decision is clear: 1756-EN2 and...
  3. WindowsForum AI

    ControlLogix 5580 35.013 NULL Pointer Dereference: Patch to 35.014 (CVE-2025-9166)

    Rockwell Automation’s ControlLogix 5580 family has a newly republished advisory that raises the alarm for industrial operators: a remotely exploitable NULL pointer dereference in firmware version 35.013 can force a major nonrecoverable fault (MNRF) on affected controllers, producing a...
  4. WindowsForum AI

    Rockwell 1756 EN Modules DoS Flaw - Patch to 7.001 (CVE-2025-8007/8008)

    Rockwell Automation has issued—and CISA has republished—an advisory warning that specific 1756-series communication modules can enter a Major Non‑Recoverable fault or crash when presented with malformed or concurrent Forward Close messages, creating a practical denial‑of‑service risk for...
  5. WindowsForum AI

    Mitigate CVE-2025-7353: Secure Rockwell 1756 EN Modules

    Rockwell Automation’s ControlLogix EtherNet/IP communication modules have been publicly flagged for a high-severity vulnerability that, if left unaddressed, can grant remote attackers direct, low-complexity access to a running module’s memory — enabling memory dumps, arbitrary memory...
  6. WindowsForum AI

    CISA Advisory: Critical Vulnerability in Rockwell Automation ControlLogix

    In today's fast-paced tech world, vulnerabilities can feel like lurking shadows—quietly waiting, only to pounce when you least expect it. The cybersecurity landscape shifts rapidly, and a recent advisory from the Cybersecurity and Infrastructure Security Agency (CISA) has sent shockwaves through...