CVE-2025-11694 - CVE House
Back to Database
Status published High CVE-2025-11694

Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities

Vulnerability Description

A security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and source IP addresses in the CIP protocol. This allows attacker to abuse the exposed Connection ID’s visible on the web interface to perform denial-of-service attacks, resulting in a minor fault.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-11694

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • This security issue was found by external researcher Tyler Lentz of Idaho National Laboratory.

Affected Vendor

Rockwell Automation

View all reports →

Affected Software

CompactLogix 5370
Vulnerable Versions:
V36

Timeline

Official Publish: June 16th, 2026
Last Modified: June 16th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.