All CVEs
Vulnerability intelligence

CVE-2026-9307

Rockwell Automation CompactLogix 5370 CWE-497

A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct malicious packets, leading to Denial-of-Service.

CVSS Score
6.3
Medium
EPSS — Exploit Probability
0.3%
Riskier than 22% of all CVEs · checked 2026-09-11
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
unknown
Check vendor advisories
NVD entry PoC / advisory

1 article across 1 outlet · first covered Jun 16, 2026 · latest Jun 16, 2026

Coverage timeline

Related CVEs — Rockwell Automation