# CVE-2025-13824

## Summary

- **CVE ID:** CVE-2025-13824
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-763
- **Published:** Dec 15, 2025
- **Last Modified:** Mar 13, 2026

## Description

A security issue exists due to improper handling of malformed CIP packets during fuzzing. The controller enters a hard fault with solid red Fault LED and becomes unresponsive. Upon power cycle, the controller will enter recoverable fault where the MS LED and Fault LED become flashing red and reports fault code 0xF019. To recover, clear the fault.

## Affected Products

- Rockwell Automation — Micro820®, Micro850®,  Micro870® (V23.011  and below)
- Rockwell Automation — Micro820®, Micro850®,  Micro870® (V12.013 and lower)
- Rockwell Automation — Micro820®, Micro850®,  Micro870® (V14.011 and lower)

## References

- [CNA](https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1766.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.34%
- **EPSS Percentile:** 26.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._