Rockwell Automation CompactLogix
2026-06-16T19:23:27Z•daf9ee04c81186f95e880ffb609fd3262e1024c6fbc555d691b6ef0d681df791
CIPCISACompactLogixControlLogix 5570DoSEtherNet/IPFLEX I/OFactoryTalkICSIoTLogix 5370MQTTNaxclowRSLinxRockwell AutomationYarboadvisoryhard-coded-credentialsindustrial control systemsmissing-authorizationvulnerability
What happened
CISA ICS advisories describe multiple vulnerabilities across Rockwell Automation industrial controllers and software (CompactLogix, Logix/ControlLogix 5370/5570, FactoryTalk PavilionX, RSLinx, FLEX I/O EtherNet/IP adapters) and several IoT/mobile platforms (Yarbo, Naxclow). Impacts include denial-of-service (including major non-recoverable faults), improper/missing authorization enabling privileged operations or account takeover, extraction of hard-coded MQTT credentials, and other memory/validation flaws. Several issues carry critical/high CVSS scores and may affect globally deployed critical
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ics_advisories
- Record identifier
- daf9ee04c81186f95e880ffb609fd3262e1024c6fbc555d691b6ef0d681df791
- Enrichment time
- 2026-06-16T19:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.