Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products

https://www.securityweek.com/wp-content/uploads/2023/05/Rockwell-Automation-e1738149646812.jpg

Rockwell Automation on Tuesday informed customers that patches or workarounds are available for more than a dozen vulnerabilities discovered across its industrial automation products.

Only one of the new advisories describes critical vulnerabilities. It covers four critical and high-severity denial-of-service (DoS) issues affecting the RSLinx Classic communications software. Exploitation can cause the RSLinx Classic service to crash, requiring a restart for recovery.

Rockwell’s advisory for CVE-2026-9637, a high-severity DoS flaw in ControlLogix and CompactLogix controllers, flags the vulnerability as exploited. However, it’s likely an error, as it’s only listed as such in the document’s header; elsewhere it’s listed as not exploited.

Hands-On Cyber-Physical Systems Training at ICS Cybersecurity Conference

CISA’s own advisory for CVE-2026-9637, published by the agency on Tuesday along with other Rockwell advisories, also says it’s not aware of exploitation.

DoS vulnerabilities have also been addressed by Rockwell in 1756-ENBT, Logix controllers (third-party component), and FactoryTalk Historian...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more