Multiple denial-of-service vulnerabilities exist in the affected product. These issues can be triggered through various crafted inputs, including malformed Class 3 messages, memory leak conditions, and other resource exhaustion scenarios. Exploitation may cause the device to become unresponsive and, in some cases, result in a major nonrecoverable fault. Recovery may require a restart.
Advisories

No advisories yet.

Fixes

Solution

Upgrade to 1756-RM3


Workaround

No workaround given by the vendor.

History

Tue, 20 Jan 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 20 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
Description Multiple denial-of-service vulnerabilities exist in the affected product. These issues can be triggered through various crafted inputs, including malformed Class 3 messages, memory leak conditions, and other resource exhaustion scenarios. Exploitation may cause the device to become unresponsive and, in some cases, result in a major nonrecoverable fault. Recovery may require a restart.
Title Rockwell Automation Recommends Upgrading From 1756-RM2 XT To 1756-RM3 XT
Weaknesses CWE-401
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-01-20T16:41:44.225Z

Reserved: 2025-12-04T14:14:42.205Z

Link: CVE-2025-14027

cve-icon Vulnrichment

Updated: 2026-01-20T16:40:53.833Z

cve-icon NVD

Status : Received

Published: 2026-01-20T14:16:07.013

Modified: 2026-01-20T14:16:07.013

Link: CVE-2025-14027

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses