A high-severity vulnerability, tracked as CVE-2025-9368, has been identified in the 432ES-IG3 Series A GuardLink® EtherNet/IP Interface. This flaw allows remote attackers to trigger a denial-of-service condition, requiring a manual power cycle to restore device functionality. The issue was discovered during internal testing and has been acknowledged by Rockwell Automation, which has released a security advisory confirming the vulnerability and its impact.
No known exploitation in the wild has been reported, and the vulnerability has been corrected according to the vendor. There are currently no workarounds available, and affected product versions have not been explicitly listed. Organizations using the 432ES-IG3 Series A are advised to review the official Rockwell Automation advisory and apply any recommended mitigations or updates to reduce risk of service disruption.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Public vulnerability reporting identified CVE-2025-9368 as a high-severity (CVSS 8.7) network-exploitable denial-of-service issue caused by uncontrolled resource allocation. The flaw requires no authentication or user interaction and can leave the device unavailable until a manual power cycle is performed.
Rockwell Automation disclosed a denial-of-service vulnerability affecting the 432ES-IG3 Series A GuardLink EtherNet/IP Interface in security advisory SD1764. The advisory recommends updating device firmware, restarting devices after updating, and monitoring device stability.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.