highOther

Rockwell Automation RSLinx Classic Multiple Denial-of-Service Vulnerabilities

First seen Sep 2, 2026 · Updated Sep 2, 2026 · CVSS 8.6

ICSOTdenial-of-serviceindustrial-control-systemsrockwell-automationCIP-protocolCVE-2026-9621CVE-2026-9622CVE-2026-9624CVE-2026-9625

Rockwell Automation RSLinx Classic versions up to 4.50 contain four vulnerabilities (integer overflow/underflow and buffer overflow conditions) exploitable via crafted CIP packets, allowing remote unauthenticated attackers to crash the RSLinx Classic service. Successful exploitation causes a denial-of-service condition requiring service restart, potentially disrupting industrial communications in critical manufacturing environments. No public exploitation has been reported at this time.

Technical Analysis

The vulnerabilities (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) stem from improper handling of malformed or oversized CIP (Common Industrial Protocol) packets, including issues in Forward Close service handling, insufficient data length validation, and buffer copy operations without size checks (CWE-190, CWE-191, CWE-120). All flaws are remotely exploitable over the network with low attack complexity and no privileges or user interaction required (AV:N/AC:L/PR:N/UI:N), with CVSS v3.1 scores ranging from 7.5 to 8.6 and CVSS v4.0 scores up to 9.2 (Critical). Exploitation results in a crash of the RSLinx Classic service, disrupting communications between SCADA/HMI systems and PLCs until manually restarted. These are pure availability-impact ICS vulnerabilities with no confidentiality or integrity impact, and are not directly relevant to AI agent systems, RAG pipelines, or LLM tool-use frameworks, as RSLinx Classic is an industrial communication middleware product with no known AI-agent integration points.

Affected Systems

Rockwell Automation RSLinx Classic versions <=4.50; fixed in version 4.60. Deployed in Critical Manufacturing sector environments worldwide, typically as OT/ICS communication middleware between SCADA/HMI systems and PLCs over CIP.

Indicators of Compromise

  • No specific IOCs (hashes, IPs, domains) provided; vulnerability is protocol-based (crafted CIP packets) rather than malware-based.

Remediation Steps

  1. 1

    Upgrade RSLinx Classic

    Update to Rockwell Automation RSLinx Classic version 4.60 or later, which corrects all four vulnerabilities.

  2. 2

    Network Segmentation

    Isolate control system networks and devices behind firewalls, separating them from business/IT networks and ensuring no direct internet exposure.

  3. 3

    Restrict Remote Access

    Use secure VPN solutions for any required remote access, keeping VPN software patched and recognizing its security depends on connected endpoints.

  4. 4

    Apply Vendor Mitigations

    For systems that cannot be immediately upgraded, apply Rockwell Automation's published security best practices (Answer ID 1085012) as compensating controls.

  5. 5

    Monitor and Report

    Monitor for anomalous CIP traffic and service crashes; report suspected malicious activity to CISA for tracking and correlation.

CVE / Advisory IDs

CVE-2026-9621CVE-2026-9622CVE-2026-9624CVE-2026-9625

Industries Most Exposed

Critical ManufacturingIndustrial AutomationEnergyWater/Wastewater

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.