Rockwell Automation CompactLogix

2026-06-16T19:23:27Zdaf9ee04c81186f95e880ffb609fd3262e1024c6fbc555d691b6ef0d681df791
CIPCISACompactLogixControlLogix 5570DoSEtherNet/IPFLEX I/OFactoryTalkICSIoTLogix 5370MQTTNaxclowRSLinxRockwell AutomationYarboadvisoryhard-coded-credentialsindustrial control systemsmissing-authorizationvulnerability

What happened

CISA ICS advisories describe multiple vulnerabilities across Rockwell Automation industrial controllers and software (CompactLogix, Logix/ControlLogix 5370/5570, FactoryTalk PavilionX, RSLinx, FLEX I/O EtherNet/IP adapters) and several IoT/mobile platforms (Yarbo, Naxclow). Impacts include denial-of-service (including major non-recoverable faults), improper/missing authorization enabling privileged operations or account takeover, extraction of hard-coded MQTT credentials, and other memory/validation flaws. Several issues carry critical/high CVSS scores and may affect globally deployed critical

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cisa_ics_advisories
Record identifier
daf9ee04c81186f95e880ffb609fd3262e1024c6fbc555d691b6ef0d681df791
Enrichment time
2026-06-16T19:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.