Rockwell Automation CompactLogix 5370是美国Rockwell Automation公司的一款可编程逻辑控制器。 Rockwell Automation CompactLogix 5370存在缓冲区错误漏洞,该漏洞源于缓冲区错误,可能导致恶意用户向控制器写入无效文件数据,造成设备进入无法恢复的严重故障。以下版本受到影响:V34.012及之前版本和V35.011及之前版本。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Rockwell Automation | CompactLogix® 5370 Compact GuardLogix® 5370 ControlLogix® 5570 GuardLogix® 5570 | V34.012 and earlier V35.011 and earlier |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Rockwell Automation | CompactLogix® 5370 Compact GuardLogix® 5370 ControlLogix® 5570 GuardLogix® 5570 | V34.012 and earlier V35.011 and earlier | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-12011 | 9.2 CRITICAL | CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow |
| CVE-2026-10573 | 6.3 MEDIUM | 1734 POINT I/OTM - Denial of Service via Malformed Inputs on CIP Object |
| CVE-2026-8085 | Rockwell Automation Arena® - Memory Corruption Vulnerability | |
| CVE-2026-8314 | Rockwell Automation Arena® - Memory Corruption Vulnerability | |
| CVE-2026-8313 | Rockwell Automation Arena® - Memory Corruption Vulnerability | |
| CVE-2026-9653 | 1756-EN2, 1756-EN3, and 1756-ENBT - Denial of Service via CIP Connection ID | |
| CVE-2026-9140 | 1718-AENTR/1719-AENTR - Denial of Service | |
| CVE-2026-10714 | Rockwell Automation FactoryTalk® Services Platform FTSP - Weak Authentication via JWT Vali | |
| CVE-2026-11917 | ThinManager® - Path Traversal via API | |
| CVE-2026-9108 | Studio 5000 Logix Designer® – Multiple Vulnerabilities | |
| CVE-2026-9128 | Studio 5000 Logix Designer® – Multiple Vulnerabilities | |
| CVE-2026-9636 | Rockwell Automation CompactLogix® 5380 ControlLogix® 5580 / 1756-EN4 Communications Module | |
| CVE-2026-9292 | Rockwell Automation FactoryTalk® DataMosaix™ Private Cloud - Stored Cross-Site Scripting | |
| CVE-2026-9127 | Studio 5000 Logix Designer® – Multiple Vulnerabilities | |
| CVE-2026-12659 | Rockwell Automation Flex 5000® Adapter - Denial of Service | |
| CVE-2025-11698 | CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow |
No comments yet