CVE-2025-13824: Rockwell Automation MICRO820, MICRO850, MICRO870
High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.
A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard fault with solid red Fault LED and becomes unresponsive. Upon power cycle, the controller will enter recoverable fault where the MS LED and Fault LED become flashing red and reports fault code 0xF019. To recover, clear the fault.
Affected products
- Rockwell Automation MICRO820, MICRO850, MICRO870: up to and including V23.011; up to and including V12.013; up to and including V14.011
Published 2025-12-15. Last modified 2026-10-07.