---
id: CVE-2025-13824
title: >-
  A security issue exists due to improper handling of malformed CIP packets
  during fuzzing
summary: >-
  A security issue exists due to improper handling of malformed CIP packets
  during fuzzing. The controller enters a hard fault with solid red Fault LED
  and becomes unresponsive. Upon power cycle, the controller will enter
  recoverable fault…
severity: none
cwe:
  - CWE-763
published: '2025-12-15'
updated: '2026-09-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13824'
references:
  - url: >-
      https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1766.html
    label: PSIRT@rockwellautomation.com
tags:
  - nvd
epss: 0.00344
epssPercentile: 0.25161
ingestedAt: '2026-09-03T03:55:24.156Z'
---

## Overview

A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard fault with solid red Fault LED and becomes unresponsive. Upon power cycle, the controller will enter recoverable fault where the MS LED and Fault LED become flashing red and reports fault code 0xF019. To recover, clear the fault.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
