You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2025-9160
About this tag
CVE-2025-9160 is a missing authentication vulnerability affecting Rockwell Automation CompactLogix 5480 controllers running specific Windows packages. Identified by CISA, it carries a CVSS v4 base score of 7.0. The low-complexity attack requires physical access to the maintenance menu and can lead to arbitrary code execution, posing serious risks to industrial control systems. Discussions on WindowsForum cover the advisory details, operational impact, and mitigation steps for organizations using these controllers.
A newly republished advisory from CISA and Rockwell Automation raises urgent operational and security flags for organizations using the CompactLogix® 5480 controller family: the devices running specific Windows packages are affected by a Missing Authentication for Critical Function vulnerability...