AI analysis
CVE-2026-9621 is a critical-severity (CVSS 4.0: 9.2) denial-of-service flaw in Rockwell Automation's RSLinx Classic, caused by improper handling of malformed packets and classified under CWE-190 (integer overflow/wraparound). A remote, unauthenticated attacker can trigger the condition by sending a specially crafted CIP packet to the service over the network. The impact is availability-only: the RSLinx Classic service crashes and must be manually restarted to recover, with no confidentiality or integrity impact per the CVSS vector, though the high subsequent-system (SA:H) score indicates downstream OT systems and processes can be disrupted. Any installation running the RSLinx Classic service where the CIP endpoint is network-reachable is affected, most typically plant-floor or engineering workstations. There is no public proof-of-concept, no CISA KEV listing, and EPSS is low (0.3%), so active exploitation is currently considered unlikely or unobserved.
What to do: Inventory hosts running RSLinx Classic and check Rockwell Automation's security advisory for the affected versions and fixed releases before patching, since no version numbers are provided in this data. Until patched, restrict network access to the RSLinx Classic service and its CIP endpoints to trusted hosts only. Monitor the service for crashes and be prepared to restart it to restore communications to downstream devices.
Affected
| Rockwell Automation RSLinx Classic | — |
Estimated exposure
large≈ tens of thousands of installations at industrial sites (deployment-pattern estimate) — RSLinx Classic is Rockwell's long-standing, widely bundled communications utility commonly installed on plant-floor and engineering stations, but no public install-count or internet-exposure scan data exists, so this is an…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover