Multiple DoS Vulnerabilities (CVE‑2025‑12011, CVE‑2025‑12012, CVE‑2025‑11698) in Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix
What It Is — CISA has identified three critical vulnerabilities in Rockwell Automation’s PLC families that could be leveraged to trigger a denial‑of‑service (DoS) condition on industrial control devices. The flaws affect firmware versions ≤ V35.015 (or ≤ V34.012/V35.011 for certain models) across CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix lines.
Exploitability — Public proof‑of‑concept code has not been released, but the advisory notes that successful exploitation is feasible on‑network. Each CVE carries a CVSS v3.1 base score of 7.5 (High), reflecting the impact on availability.
Affected Products
- CompactLogix 5370, 5380, 5480
- Compact GuardLogix 5370, 5380
- ControlLogix 5570, 5580
- GuardLogix 5570, 5580
All listed with firmware ≤ V35.015 (or the earlier V34.012/V35.011 thresholds).
Why It Matters for Compliance & Audit Readiness
- Control Environment – SOC 2 CC6.1 (System Operations) requires documented, tested controls that prevent loss of availability; unpatched PLC firmware is a direct control gap.
- Continuous Monitoring – Evidence of firmware version and patch status must be captured in real time to satisfy audit evidence requirements.
- Due Diligence – Demonstrating that you have an inventory of critical OT assets and a formal patch‑management process is increasingly demanded by enterprise customers during SOC 2 assessments.
Recommended Actions
- Verify firmware versions on all affected PLCs against the list above.
- Apply Rockwell’s remediation patches immediately; if patches are unavailable, implement compensating network segmentation and intrusion‑detection rules.
- Update your asset‑management database and map the remediation to SOC 2 CC6.1 controls.
- Enable continuous evidence collection for firmware state (e.g., via Verisq’s Control Mapping module) to streamline future audits.
Source: CISA Advisory – ICSA‑26‑197‑06