IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Rockwell Automation CompactLogix 5380 ControlLogix 5580 / 1756-EN4TR Communications Module

MEDIUM
CVSS 5.9
Date 2026-07-30T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-9636 5.9 medium
A security issue exists within CompactLogix 5380, ControlLogix 5580, and EN4TR communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a Certificate Revocation List (CRL). This could allow a network-based attacker to establish a connection using a certificate that should be untrusted, potentially bypassing CIP Security protections.

// Affected Products (2)

Vendor Product Asset Type Purdue Level Firmware
Rockwell Automation Unknown plc
L1
v.32.011
Rockwell Automation Unknown plc
L1
35.013

// Remediations (5)

Patch: Rockwell Automation recommend users update to the following versions: ControlLogix 5580: Update to V
Rockwell Automation recommend users update to the following versions: ControlLogix 5580: Update to V38.011
Patch: 1756-EN4TR: Update to V8.001
1756-EN4TR: Update to V8.001
Patch: GuardLogix 5580: Update to V38.011
GuardLogix 5580: Update to V38.011
Patch: Compact GuardLogix 5380: Update to V38.011
Compact GuardLogix 5380: Update to V38.011
Patch: CompactLogix 5380: Update to V38.011
CompactLogix 5380: Update to V38.011

// References