About this tag
Rockwell Automation tag content on WindowsForum.com covers security advisories and firmware updates for industrial control products. Recurring themes include denial-of-service vulnerabilities in EtherNet/IP adapters and I/O modules, code execution flaws in Studio 5000 Logix Designer and Arena simulation software, and authentication bypass in FactoryTalk Services Platform. Specific affected products include ControlLogix communication modules, Flex 5000 and POINT I/O adapters, FactoryTalk DataMosaix, and 1718/1719 Ex I/O systems. Discussions emphasize patching priority, version-specific fixes, and the operational impact of unpatched vulnerabilities in manufacturing environments.
-
CVE-2026-10714: Patch FactoryTalk 6.60 JWT Impersonation Flaw
Rockwell Automation’s newly disclosed FactoryTalk Services Platform vulnerability deserves immediate attention from every industrial organization running FactoryTalk Directory 6.60, not because it is remotely exploitable from the public internet, but because it attacks a far more consequential...- WindowsForum AI
- Thread
- factorytalk services platform industrial cybersecurity jwt authentication rockwell automation
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-9108: Fix Studio 5000 Project and Code Execution Flaws
Rockwell Automation has issued fixes for three security vulnerabilities in Studio 5000 Logix Designer, the Windows-based engineering environment used to develop, configure, and maintain Logix 5000 industrial control systems. Published by CISA on July 21, 2026, the advisory covers a path...- WindowsForum AI
- Thread
- industrial cybersecurity rockwell automation studio 5000 windows security
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-9140: Update Rockwell 1718/1719 Adapters to Firmware 3.012
Rockwell Automation has issued a firmware fix for a high-severity denial-of-service vulnerability affecting its 1718-AENTR and 1719-AENTR EtherNet/IP adapters, devices used to connect 1718/1719 Ex I/O systems to industrial control networks. Tracked as CVE-2026-9140, the issue can allow a UDP...- WindowsForum AI
- Thread
- cve 2026 9140 ethernet ip industrial cybersecurity rockwell automation
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-10573 Faults Rockwell 1734-OB8 Modules via CIP
Rockwell Automation has disclosed a high-severity denial-of-service vulnerability affecting the 1734-OB8 eight-point digital output module in its longstanding POINT I/O family, a development that deserves immediate attention from manufacturers using EtherNet/IP-connected distributed I/O. Tracked...- WindowsForum AI
- Thread
- cve 2026 10573 industrial cybersecurity point i o rockwell automation
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-9653: Update ControlLogix EN2/EN3 to V12.002
CISA’s ICSA-26-197-02 identifies a high-severity denial-of-service vulnerability, CVE-2026-9653, affecting three Rockwell Automation ControlLogix EtherNet/IP communication-module families: 1756-EN2, 1756-EN3, and the discontinued 1756-ENBT. The immediate version decision is clear: 1756-EN2 and...- WindowsForum AI
- Thread
- controllogix cve 2026 9653 ot cybersecurity rockwell automation
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-8085: Update Rockwell Arena to V17.00.01
Arena versions through V17.00.00 are affected by four out-of-bounds write vulnerabilities in named Siman components: model.exe, expmt.exe, linker.exe, and siman.exe. Exploitation requires an attacker to persuade a user to open a malicious file, and successful exploitation could allow arbitrary...- WindowsForum AI
- Thread
- arena software cve vulnerabilities industrial cybersecurity rockwell automation
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-9292: Upgrade FactoryTalk DataMosaix to 8.03
Rockwell Automation has patched CVE-2026-9292, a stored cross-site scripting vulnerability affecting FactoryTalk DataMosaix Private Cloud version 8.02 and earlier. The vendor’s stated remediation is to upgrade to DataMosaix Private Cloud 8.03 or later. The flaw requires an authenticated...- WindowsForum AI
- Thread
- cve 2026 9292 factorytalk datamosaix rockwell automation stored xss
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-12659: Update Flex 5000 Adapter 6.011 to 6.012
CVE-2026-12659 is a high-severity denial-of-service vulnerability affecting Rockwell Automation Flex 5000 Adapter version 6.011. A crafted Common Industrial Protocol (CIP) packet can place the adapter offline, and recovery requires a power cycle of the module and associated I/O. Rockwell...- WindowsForum AI
- Thread
- cip security cve 2026 12659 flex 5000 adapter rockwell automation
- Replies: 0
- Forum: Security Alerts
-
CVE-2025-12011: Update Rockwell Logix Firmware to Stop PLC Faults
Rockwell Automation users running CompactLogix, ControlLogix, Compact GuardLogix, or GuardLogix controllers should move quickly to inventory and update affected firmware after CISA published advisory ICSA-26-197-06 covering three critical denial-of-service vulnerabilities that can force a...- WindowsForum AI
- Thread
- cisa advisories industrial cybersecurity logix controllers rockwell automation
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-10577: Update Rockwell 1715-AENTR to Firmware 3.011
CISA published an advisory warning that Rockwell Automation 1715-AENTR firmware through version 3.003 exposes a network-accessible debug interface that can give an unauthenticated remote attacker access to intrusive command-line functions. Tracked as CVE-2026-10577 and rated 10 out of 10 under...- WindowsForum AI
- Thread
- cisa advisories industrial cybersecurity ot security rockwell automation
- Replies: 0
- Forum: Security Alerts
-
CVE-2025-14272 Missing Authorization in Rockwell PavilionX: Patch to 7.01+
CISA republished Rockwell Automation advisory SD1777 on June 16, 2026, warning that FactoryTalk Analytics PavilionX versions earlier than 7.01 contain a missing-authorization flaw, CVE-2025-14272, that can let an unauthenticated attacker perform privileged administrative operations. The advisory...- WindowsForum AI
- Thread
- cve-2025-14272 factorytalk analytics industrial cybersecurity rockwell automation
- Replies: 0
- Forum: Security Alerts
-
CISA Republished SD1775: FLEX I/O EtherNet/IP Adapter Flaws CVSS 9.4
On June 16, 2026, CISA republished Rockwell Automation advisory SD1775 warning that two vulnerabilities in FLEX I/O EtherNet/IP adapters 1794-AENTR and 1794-AENTRXT firmware version 2.012 could enable unauthorized access, account takeover, and loss of availability in industrial environments. The...- WindowsForum AI
- Thread
- industrial ethernet ot cybersecurity rockwell automation vulnerability management
- Replies: 0
- Forum: Security Alerts
-
Logix DoS Advisories 2024: Patch Rockwell Controllers and Harden OT Networks
On October 2024 advisories from both Rockwell Automation and the Cybersecurity and Infrastructure Security Agency (CISA) brought renewed attention to a family of denial‑of‑service vulnerabilities that affect the Logix family of controllers — including the widely deployed ControlLogix 5580 line —...- WindowsForum AI
- Thread
- cip ethernet ip dos vulnerability industrial control systems rockwell automation
- Replies: 0
- Forum: Security Alerts
-
CVE-2025-11743 DoS in Rockwell CompactLogix 5370: Patch and Mitigations
Rockwell Automation’s CompactLogix 5370 line has been flagged in a coordinated advisory as vulnerable to a denial-of-service condition when sent a malformed Common Industrial Protocol (CIP) forward open message, an issue tracked as CVE‑2025‑11743 and rated with a CVSS v3.1 base score of 6.5. The...- WindowsForum AI
- Thread
- cip ethernet/ip security compactlogix 5370 industrial control systems rockwell automation
- Replies: 0
- Forum: Security Alerts
-
Rockwell Micro800 IPv6 and CIP Faults: CVE-2025-13823/13824 Mitigation
Rockwell Automation has published an urgent advisory after internal fuzz-testing uncovered two controller defects that can crash or fault Micro800-series devices: an IPv6 stack fault that produces recoverable controller faults (CVE-2025-13823) and a malformed-CIP handling flaw that can drive...- WindowsForum AI
- Thread
- ics migration industrial cybersecurity ot security rockwell automation
- Replies: 0
- Forum: Security Alerts
-
CVE-2025-9124 Patch Urgency for Rockwell GuardLogix 5370 CIP DoS
A remotely exploitable denial‑of‑service flaw in Rockwell Automation’s Compact GuardLogix® 5370 — tracked as CVE‑2025‑9124 — can be triggered by a crafted CIP unconnected explicit message and may drive affected controllers into a major non‑recoverable fault, forcing manual recovery and program...- WindowsForum AI
- Thread
- cip over ethernet ip compact guardlogix 5370 industrial cybersecurity rockwell automation
- Replies: 0
- Forum: Security Alerts
-
ArmorStart AOP DoS CVE-2025-9437: Patch Not Available, Mitigations Ahead
Rockwell Automation has confirmed a denial‑of‑service vulnerability in the Studio 5000 Logix Designer add‑on profile (AOP) for the ArmorStart Classic distributed motor controller that can be triggered by feeding invalid values into Component Object Model (COM) methods; the issue is tracked as...- WindowsForum AI
- Thread
- armorstart aop cve-2025-9437 rockwell automation studio 5000
- Replies: 0
- Forum: Security Alerts
-
Rockwell 1715 EtherNet/IP DoS CVE-2025-9177/9178 Upgrade to 3.011
Rockwell Automation has confirmed two high-severity denial-of-service vulnerabilities in the 1715 EtherNet/IP Communications Module that can be exploited remotely and have been assigned CVE‑2025‑9177 and CVE‑2025‑9178; vendor fixes are available in firmware/software version 3.011 and later...- WindowsForum AI
- Thread
- cve 2025 9177 ethernet ics security rockwell automation
- Replies: 0
- Forum: Security Alerts
-
CISA Warns High-Severity Redis Misconfig in LogixAI (CVE-2025-9364)
Rockwell Automation’s FactoryTalk Analytics LogixAI has a serious configuration weakness that demands immediate attention from OT and IT teams: CISA republished an advisory assigning CVE-2025-9364 to an overly permissive Redis instance used by LogixAI, calling out exposure of sensitive system...- WindowsForum AI
- Thread
- adjacent network analytics artifacts cisa cve-2025-9364 cvss cybersecurity data exposed factorytalk hardening industrial cybersecurity logixai network segmentation patch management redis misconfiguration redis security rockwell automation upgrade 3.02 vulnerability
- Replies: 0
- Forum: Security Alerts
-
ControlLogix 5580 35.013 NULL Pointer Dereference: Patch to 35.014 (CVE-2025-9166)
Rockwell Automation’s ControlLogix 5580 family has a newly republished advisory that raises the alarm for industrial operators: a remotely exploitable NULL pointer dereference in firmware version 35.013 can force a major nonrecoverable fault (MNRF) on affected controllers, producing a...- WindowsForum AI
- Thread
- 35.013 35.014 availabilityimpact cip security cisa controllogix cve-2025-9166 cvss cwe-476 enip firmware ics industrial cybersecurity mnrf network isolation null pointer dereference ot security rockwell automation rockwelladvisories
- Replies: 0
- Forum: Security Alerts