IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Rockwell Automation Logix Platform

HIGH
CVSS 7.5
Date 2026-09-01T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-9637 7.5 high
A denial-of-service vulnerability exists in the affected Logix platforms due to improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover.

// Affected Products (2)

Vendor Product Asset Type Purdue Level Firmware
Rockwell Automation Unknown plc
L1
35.013
Rockwell Automation Unknown plc
L1
v.32.011

// Remediations (5)

Patch: Rockwell Automation recommends users update to firmware version 35.014.
Rockwell Automation recommends users update to firmware version 35.014.
Mitigation: Customers using the affected software who are not able to upgrade to one of the corrected versions s
Customers using the affected software who are not able to upgrade to one of the corrected versions should use Rockwell Automation's security best practices.
Patch: Rockwell Automation recommends users update to firmware version 34.015.
Rockwell Automation recommends users update to firmware version 34.015.
Patch: Rockwell Automation recommends users update to firmware version 36.013.
Rockwell Automation recommends users update to firmware version 36.013.
Patch: Rockwell Automation recommends users update to firmware version V37.011.
Rockwell Automation recommends users update to firmware version V37.011.

// References