8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Description
Multiple denial-of-service vulnerabilities exist in the affected product. These issues can be triggered through various crafted inputs, including malformed Class 3 messages, memory leak conditions, and other resource exhaustion scenarios. Exploitation may cause the device to become unresponsive and, in some cases, result in a major nonrecoverable fault. Recovery may require a restart.
AI Analysis
Multiple denial-of-service vulnerabilities in Rockwell Automation ControlLogix Redundancy Enhanced Module allow for potential resource exhaustion and device unresponsiveness through crafted inputs.
Basic Information
ID
CVE-2025-14027
Source
Rockwell
Published
Jan 20, 2026 at 13:56
Affected Product
Vendor
Rockwell Automation
Product
ControlLogix® Redundancy Enhanced Module
Version
All Versions
Affected Versions
Rockwell Automation ControlLogix® Redundancy Enhanced Module All Versions
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
Rockwell Automation
Product
ControlLogix Redundancy Enhanced Module
Version
All Versions