PT-2026-58085 · Rockwell Automation · Guardlogix 5580+4
CVE-2026-9636
·
Published
2026-07-14
·
Updated
2026-09-01
CVSS v4.0
8.2
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
CompactLogix 5380 (affected versions not specified)
ControlLogix 5580 (affected versions not specified)
EN4 communication modules (affected versions not specified)
GuardLogix 5580 (affected versions not specified)
Compact GuardLogix 5380 (affected versions not specified)
Description
An issue exists in the handling of CIP Security certificate revocation. The controllers fail to properly reject certificates signed by an intermediate certificate that has been revoked via a Certificate Revocation List (CRL), which is a list of digital certificates that have been cancelled by the issuing authority before their scheduled expiration date. This flaw could allow a network-based attacker to establish a connection using an untrusted certificate and bypass CIP Security protections.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Compact Guardlogix 5380
Compactlogix 5380
Controllogix 5580
En4 Communication Modules
Guardlogix 5580