The Cybersecurity and Infrastructure Security Agency (CISA) and Rockwell Automation have issued a coordinated industrial control systems advisory (ICSA-26-288-03) warning of a dangerous denial-of-service vulnerability (CVE-2026-49821, CVSS 8.6) impacting Allen-Bradley ControlLogix 5580 and GuardLogix 5580 programmable automation controllers (PACs). The vulnerability allows network threat actors to send crafted packets that force the controller into an unrecoverable CPU fault, freezing industrial assembly lines, automotive presses, and packaging machinery.
Technical Root Cause: CIP Unconnected Message Routing Lockup (CWE-400)
ControlLogix 5580 controllers utilize the Common Industrial Protocol (CIP) encapsulated over EtherNet/IP (TCP/UDP port 44818) to coordinate high-speed motion axes, I/O communications, and distributed messaging across manufacturing plant floors. When a remote engineering workstation connects to a controller, it dispatches CIP Unconnected Send requests containing routing path segments.
The flaw resides in the controller's CIP communications firmware parser. When an incoming CIP message contains recursive or circular routing path descriptors with mismatched length indicators, the parser enters an unbounded loop inside a high-priority real-time interrupt service routine (ISR):
// Pseudocode of vulnerable CIP routing path handler in ControlLogix firmware
void ParseCipRoutingPath(uint8_t* path_bytes, uint16_t path_len) {
uint16_t offset = 0;
while (offset < path_len) {
uint8_t segment_type = path_bytes[offset];
uint8_t segment_len = path_bytes[offset + 1];
// Defect: Zero-length or cyclic self-referencing path causes infinite loop
if (segment_len == 0) {
continue; // Infinite loop locks watchdog timer
}
offset += segment_len;
}
}
Because the interrupt routine monopolizes the processor core, the hardware watchdog timer expires, triggering a Major Non-Recoverable Fault (MNRF). The controller immediately transitions to a faulted state, shutting down all active outputs and terminating plant machinery.
Industrial Safety & Operational Impact
While GuardLogix safety controllers are designed to fail into a predetermined safe state (de-energizing outputs to prevent physical injury), unexpected line stoppages in heavy manufacturing environments carry severe consequences:
- Line Stoppage and Scrap Generation: Sudden halts during high-temperature injection molding or continuous metal stamping ruin work-in-progress materials and damage tooling.
- Protracted Manual Recovery: Clearing an MNRF requires an on-site engineer to physically power-cycle the controller chassis, clear faults via Studio 5000 Logix Designer, and reload the project file.
- Remote Exploitation Surface: If industrial routers bridge EtherNet/IP traffic between corporate IT and OT zones, an attacker on the enterprise network can knock out multiple plants simultaneously.
Remediation Playbook for Automation Engineers
- Flash Firmware Update: Upgrade ControlLogix 5580 and GuardLogix 5580 controllers to firmware revision v35.014 or higher.
- CIP Protocol Filtering: Configure industrial managed switches and firewalls (such as Stratix switches) to inspect EtherNet/IP traffic and drop CIP Unconnected Send packets originating outside authorized engineering IP ranges.
- Enforce FactoryTalk Security: Enable CIP Security with cryptographic authentication and integrity verification to ensure only signed controllers and engineering tools can communicate over TCP port 44818.



