CVE Database
/

CVE-2025-9042

Back to search

CVE-2025-9042

Published: Aug 14, 2025

Modified: Aug 14, 2025

PUBLISHED

Description

A security issue exists due to improper handling of CIP Class 32’s request when a module is inhibited on the 5094-IY8 device. It causes the module to enter a fault state with the Module LED flashing red. Upon un-inhibiting, the module returns a connection fault (Code 16#0010), and the module cannot recover without a power cycle.

VendorProductVersions

Rockwell Automation

FLEX 5000 I/O

affected
Version 2.011 or below

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now