HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Multiple DoS Vulnerabilities (CVE‑2025‑12011/12012/11698) Discovered in Rockwell Automation PLCs

CISA reports three high‑severity CVEs affecting Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix firmware, enabling denial‑of‑service attacks. For SOC 2‑ready organizations, unpatched PLCs represent a control gap that must be documented and continuously monitored.

LiveThreat™ Intelligence · 📅 July 16, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
cisa.gov

Multiple DoS Vulnerabilities (CVE‑2025‑12011, CVE‑2025‑12012, CVE‑2025‑11698) in Rockwell Automation CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix

What It Is — CISA has identified three critical vulnerabilities in Rockwell Automation’s PLC families that could be leveraged to trigger a denial‑of‑service (DoS) condition on industrial control devices. The flaws affect firmware versions ≤ V35.015 (or ≤ V34.012/V35.011 for certain models) across CompactLogix, ControlLogix, Compact GuardLogix and GuardLogix lines.

Exploitability — Public proof‑of‑concept code has not been released, but the advisory notes that successful exploitation is feasible on‑network. Each CVE carries a CVSS v3.1 base score of 7.5 (High), reflecting the impact on availability.

Affected Products

  • CompactLogix 5370, 5380, 5480
  • Compact GuardLogix 5370, 5380
  • ControlLogix 5570, 5580
  • GuardLogix 5570, 5580

All listed with firmware ≤ V35.015 (or the earlier V34.012/V35.011 thresholds).

Why It Matters for Compliance & Audit Readiness

  • Control Environment – SOC 2 CC6.1 (System Operations) requires documented, tested controls that prevent loss of availability; unpatched PLC firmware is a direct control gap.
  • Continuous Monitoring – Evidence of firmware version and patch status must be captured in real time to satisfy audit evidence requirements.
  • Due Diligence – Demonstrating that you have an inventory of critical OT assets and a formal patch‑management process is increasingly demanded by enterprise customers during SOC 2 assessments.

Recommended Actions

  • Verify firmware versions on all affected PLCs against the list above.
  • Apply Rockwell’s remediation patches immediately; if patches are unavailable, implement compensating network segmentation and intrusion‑detection rules.
  • Update your asset‑management database and map the remediation to SOC 2 CC6.1 controls.
  • Enable continuous evidence collection for firmware state (e.g., via Verisq’s Control Mapping module) to streamline future audits.

Source: CISA Advisory – ICSA‑26‑197‑06

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-26-197-06

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →