Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
industrial-control-system-vulnerabilitycritical-infrastructure-threatidentity-authentication-vulnerabilitywidely-deployed-product-advisory

Rockwell Automation ICS Products Hit by Authentication, Authorization, DoS, and RCE Flaws

Updated 4d agoFirst seen Jun 16, 202613 sources

CISA republished multiple Rockwell Automation advisories covering vulnerabilities across FactoryTalk Analytics PavilionX, RSLinx Classic, CompactLogix 5370, Logix 5370/5570 controllers, and FLEX I/O EtherNet/IP Adapters used in critical manufacturing environments worldwide. The issues include an authorization bypass in PavilionX (CVE-2025-14272) that could let an unauthenticated attacker perform privileged administrative actions, and a third-party flaw in RSLinx Classic (CVE-2020-13573) tied to out-of-bounds read and stack-based buffer overflow conditions that could cause denial of service or enable remote arbitrary code execution.

Additional advisories detail multiple CIP-related denial-of-service weaknesses in CompactLogix and Logix controllers, including CVE-2026-11317, where crafted CIP messages can trigger major nonrecoverable faults requiring a program download, as well as sequence-number, source-IP, and connection-ID issues that can induce controller faults. CISA also warned that FLEX I/O EtherNet/IP Adapters version 2.012 are affected by CVE-2026-0646, which can fault devices through malformed CIP requests, and CVE-2026-0647, a critical authentication bypass in the embedded web server that allows password changes through a crafted HTTP GET request, potentially leading to account takeover and loss of availability; CISA said no known public exploitation had been reported and urged operators to isolate control networks, reduce internet exposure, and secure remote access with firewalls and updated VPNs.

Share:
Rockwell Automation ICS Products Hit by Authentication, Authorization, DoS, and RCE Flaws
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

12 events from the most recent confirmed update back to the earliest known activity.

12 EVENTS
Jun 17, 20266d ago

Rockwell patches FactoryTalk Historian vulnerabilities

Rockwell Automation released patches for vulnerabilities affecting FactoryTalk Historian. SecurityWeek reported that CISA distributed Rockwell advisories for other products on June 16, 2026, but did not publish an advisory for the FactoryTalk Historian issues.

Rockwell Automation Patches Vulnerabilities in ICS Controllers and Software - SecurityWeek
Jun 16, 20267d ago

Rockwell Automation publishes security advisory SD1777

Rockwell Automation published security advisory SD1777 on 2026-06-16. The provided reference includes the advisory identifier and publication date but no synopsis details.

SD1777 | Security Advisory | Rockwell Automation | US

Rockwell Automation publishes security advisory SD1776

Rockwell Automation published security advisory SD1776 on 2026-06-16. The provided reference includes the advisory identifier and publication date but no synopsis details.

SD1776 | Security Advisory | Rockwell Automation | US

Rockwell Automation publishes security advisory SD1775

Rockwell Automation published security advisory SD1775 on 2026-06-16. The provided reference includes the advisory identifier and publication date but no synopsis details.

SD1775 | Security Advisory | Rockwell Automation | US

Rockwell Automation publishes security advisory SD1774

Rockwell Automation published security advisory SD1774 on 2026-06-16. The provided reference includes the advisory identifier and publication date but no synopsis details.

SD1774 | Security Advisory | Rockwell Automation | US

Rockwell Automation publishes security advisory SD1773

Rockwell Automation published security advisory SD1773 on 2026-06-16. The provided reference includes the advisory identifier and publication date but no synopsis details.

SD1773 | Security Advisory | Rockwell Automation | US

Rockwell Automation publishes security advisory SD1772

Rockwell Automation published security advisory SD1772 on 2026-06-16. The provided reference includes the advisory identifier and publication date but no synopsis details.

SD1772 | Security Advisory | Rockwell Automation | US

CISA republishes advisory for FLEX I/O EtherNet/IP Adapter flaws

On 2026-06-16, CISA republished a Rockwell Automation advisory covering CVE-2026-0646 and CVE-2026-0647 in FLEX I/O EtherNet/IP Adapters 1794-AENTR and 1794-AENTRXT version 2.012. The vulnerabilities include a denial-of-service condition and a critical authentication bypass in the embedded web server that can let an unauthenticated attacker change the web interface password.

Rockwell Automation FLEX I/O EtherNet/IP Adapters | CISA

CISA republishes advisory for CompactLogix CIP denial-of-service issues

On 2026-06-16, CISA republished a Rockwell Automation advisory describing two vulnerabilities in CompactLogix 5370 L1, L2, and L3 controllers earlier than V38.011. The issues involve improper validation in the CIP protocol and exposure of CIP Connection IDs through the web interface, enabling denial-of-service conditions that cause a minor fault.

Rockwell Automation CompactLogix | CISA

CISA republishes advisory for Logix 5370 and 5570 controller DoS bug

On 2026-06-16, CISA republished a Rockwell Automation advisory for CVE-2026-11317 affecting multiple Logix 5370 and 5570 controller families. The flaw can be triggered with a crafted CIP message to cause a major nonrecoverable fault, and CISA said no known public exploitation had been reported at the time of publication.

Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP | CISA

CISA republishes advisory for RSLinx Classic vulnerability

On 2026-06-16, CISA republished a Rockwell Automation advisory for RSLinx Classic 4.50.00 and earlier covering CVE-2020-13573. The advisory said exploitation could cause denial of service and also described a stack-based buffer overflow that could allow remote arbitrary code execution; no known public exploitation was reported to CISA at publication time.

Rockwell Automation RSLinx | CISA

CISA republishes advisory for FactoryTalk Analytics PavilionX flaw

On 2026-06-16, CISA republished a Rockwell Automation advisory describing CVE-2025-14272, a missing-authorization flaw in FactoryTalk Analytics PavilionX versions earlier than 7.01 that could let an unauthenticated attacker perform privileged administrative actions. CISA said no known public exploitation specifically targeting the issue had been reported at the time of publication.

Rockwell Automation FactoryTalk Analytics PavilionX | CISA
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Rockwell Automation ICS Products Hit by Authentication, Authorization, DoS, and RCE Flaws | Mallory