CVE-2025-11694

HIGH

Rockwell CompactLogix 5370 v36 - CIP Sequence Validation Denial of Service

Title source: manual
STIX 2.1

Description

A security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and source IP addresses in the CIP protocol. This allows attacker to abuse the exposed Connection ID’s visible on the web interface to perform denial-of-service attacks, resulting in a minor fault.

Scores

CVSS v4 8.7
EPSS 0.0017
EPSS Percentile 6.7%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-354
Status published
Products (1)
Rockwell Automation/CompactLogix 5370 V36
Published Jun 16, 2026
Tracked Since Jun 16, 2026