PT-2026-49704 · Rockwell Automation · Compactlogix 1769-L

CVE-2025-11694

·

Published

2026-06-16

·

Updated

2026-06-16

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions 1769 CompactLogix controllers (affected versions not specified)
Description A security issue exists due to missing validation of sequence numbers and source IP addresses in the Common Industrial Protocol (CIP). An attacker can abuse exposed Connection IDs visible on the web interface to perform denial-of-service attacks, which results in a minor fault.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-11694

Affected Products

Compactlogix 1769-L