Rockwell Automation CompactLogix是美国Rockwell Automation基金会的一款可编程自动化控制器。 Rockwell Automation CompactLogix存在加密问题漏洞,该漏洞源于CIP Security证书吊销处理问题,控制器未能正确拒绝由已吊销中间证书签名的证书,可能导致基于网络的攻击者使用本应不受信任的证书建立连接,绕过CIP Security保护。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Rockwell Automation | ControlLogix® 5580, CompactLogix® 5380, GuardLogix® 5580, Compact GuardLogix® 5380, 1756-EN4TR | Version 36 - Version 37 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Rockwell Automation | ControlLogix® 5580, CompactLogix® 5380, GuardLogix® 5580, Compact GuardLogix® 5380, 1756-EN4TR | Version 36 - Version 37 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-12011 | 9.2 CRITICAL | CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow |
| CVE-2026-10573 | 6.3 MEDIUM | 1734 POINT I/OTM - Denial of Service via Malformed Inputs on CIP Object |
| CVE-2026-8085 | Rockwell Automation Arena® - Memory Corruption Vulnerability | |
| CVE-2026-8314 | Rockwell Automation Arena® - Memory Corruption Vulnerability | |
| CVE-2026-8313 | Rockwell Automation Arena® - Memory Corruption Vulnerability | |
| CVE-2026-9653 | 1756-EN2, 1756-EN3, and 1756-ENBT - Denial of Service via CIP Connection ID | |
| CVE-2026-9140 | 1718-AENTR/1719-AENTR - Denial of Service | |
| CVE-2026-10714 | Rockwell Automation FactoryTalk® Services Platform FTSP - Weak Authentication via JWT Vali | |
| CVE-2025-12012 | CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow | |
| CVE-2026-11917 | ThinManager® - Path Traversal via API | |
| CVE-2026-9108 | Studio 5000 Logix Designer® – Multiple Vulnerabilities | |
| CVE-2026-9128 | Studio 5000 Logix Designer® – Multiple Vulnerabilities | |
| CVE-2026-9292 | Rockwell Automation FactoryTalk® DataMosaix™ Private Cloud - Stored Cross-Site Scripting | |
| CVE-2026-9127 | Studio 5000 Logix Designer® – Multiple Vulnerabilities | |
| CVE-2026-12659 | Rockwell Automation Flex 5000® Adapter - Denial of Service | |
| CVE-2025-11698 | CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow |
No comments yet