Micro820®, Micro850®, Micro870® – Specialized Fuzzing Vulnerabilities
Summary
| CVE | CVE-2025-13824 |
|---|---|
| State | PUBLISHED |
| Assigner | Rockwell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-12-15 16:15:50 UTC |
| Updated | 2026-09-03 03:15:19 UTC |
| Description | A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard fault with solid red Fault LED and becomes unresponsive. Upon power cycle, the controller will enter recoverable fault where the MS LED and Fault LED become flashing red and reports fault code 0xF019. To recover, clear the fault. |
Risk And Classification
Primary CVSS: v4.0 8.7 HIGH from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-763 | CWE-763 CWE-763: Release of Invalid Pointer or Reference
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 8.7 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 8.7 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Rockwell Automation | Micro820 Micro850 Micro870 | affected V23.011 and below | Not specified |
| CNA | Rockwell Automation | Micro820 Micro850 Micro870 | affected V12.013 and lower | Not specified |
| CNA | Rockwell Automation | Micro820 Micro850 Micro870 | affected V14.011 and lower | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1766.html | [email protected] | www.rockwellautomation.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Additional Advisory Data
Solutions
CNA: V23.012 https://compatibility.rockwellautomation.com/Pages/MultiProductFindDownloads.aspx , Migrate to the newer Micro850/870 controllers (L50E/L70E V23.012 https://compatibility.rockwellautomation.com/Pages/MultiProductFindDownloads.aspx ) , Migrate to the newer Micro820 controllers (L20E V23.011)