Rockwell Automation RSLinx Classic Multiple Denial-of-Service Vulnerabilities
First seen Sep 2, 2026 · Updated Sep 2, 2026 · CVSS 8.6
Rockwell Automation RSLinx Classic versions up to 4.50 contain four vulnerabilities (integer overflow/underflow and buffer overflow conditions) exploitable via crafted CIP packets, allowing remote unauthenticated attackers to crash the RSLinx Classic service. Successful exploitation causes a denial-of-service condition requiring service restart, potentially disrupting industrial communications in critical manufacturing environments. No public exploitation has been reported at this time.
Technical Analysis
The vulnerabilities (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) stem from improper handling of malformed or oversized CIP (Common Industrial Protocol) packets, including issues in Forward Close service handling, insufficient data length validation, and buffer copy operations without size checks (CWE-190, CWE-191, CWE-120). All flaws are remotely exploitable over the network with low attack complexity and no privileges or user interaction required (AV:N/AC:L/PR:N/UI:N), with CVSS v3.1 scores ranging from 7.5 to 8.6 and CVSS v4.0 scores up to 9.2 (Critical). Exploitation results in a crash of the RSLinx Classic service, disrupting communications between SCADA/HMI systems and PLCs until manually restarted. These are pure availability-impact ICS vulnerabilities with no confidentiality or integrity impact, and are not directly relevant to AI agent systems, RAG pipelines, or LLM tool-use frameworks, as RSLinx Classic is an industrial communication middleware product with no known AI-agent integration points.
Affected Systems
Rockwell Automation RSLinx Classic versions <=4.50; fixed in version 4.60. Deployed in Critical Manufacturing sector environments worldwide, typically as OT/ICS communication middleware between SCADA/HMI systems and PLCs over CIP.
Indicators of Compromise
- No specific IOCs (hashes, IPs, domains) provided; vulnerability is protocol-based (crafted CIP packets) rather than malware-based.
Remediation Steps
- 1
Upgrade RSLinx Classic
Update to Rockwell Automation RSLinx Classic version 4.60 or later, which corrects all four vulnerabilities.
- 2
Network Segmentation
Isolate control system networks and devices behind firewalls, separating them from business/IT networks and ensuring no direct internet exposure.
- 3
Restrict Remote Access
Use secure VPN solutions for any required remote access, keeping VPN software patched and recognizing its security depends on connected endpoints.
- 4
Apply Vendor Mitigations
For systems that cannot be immediately upgraded, apply Rockwell Automation's published security best practices (Answer ID 1085012) as compensating controls.
- 5
Monitor and Report
Monitor for anomalous CIP traffic and service crashes; report suspected malicious activity to CISA for tracking and correlation.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.