ZeroHour

CVE-2026-9622

large

Unauthenticated Denial-of-Service in Rockwell Automation RSLinx Classic

CVSS 4.0
8.7 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-9622 is a remotely exploitable denial-of-service flaw in Rockwell Automation RSLinx Classic, an industrial communications and OPC server product used alongside Allen-Bradley controllers. An attacker with network reachability to the service can send a crafted CIP (Common Industrial Protocol) packet targeting the Forward Close service, which the software mishandles due to an integer coercion error (CWE-191). The result is a crash of the RSLinx Classic service, and a manual restart of the service is required to restore operations; there is no confidentiality or integrity impact and no indication of code execution. The CVSS 4.0 score of 8.7 (High) reflects unauthenticated network access with a high availability impact on the vulnerable system. No public proof-of-concept exists, the issue is not in CISA KEV, and EPSS estimates the 30-day exploitation probability at about 0.3 percent, so no exploitation is currently known.

What to do: Monitor Rockwell Automation's security advisory for CVE-2026-9622 and upgrade RSLinx Classic to a patched release once one is published, since no fixed version is given in the available data. In the meantime, restrict network access to the CIP/EtherNet-IP service used by RSLinx (commonly TCP/44818 and related EtherNet/IP traffic) from untrusted networks and keep it segmented from corporate or internet-facing zones. Ensure staff know the recovery procedure (restart the RSLinx Classic service) and monitor for unexpected service crashes as an indicator of probing or exploitation.

Affected
Rockwell Automation RSLinx Classic
Estimated exposure
largeon the order of 100,000+ installations across tens of thousands of industrial sites (estimate) — RSLinx Classic has been the long-standing bundled communications/OPC component across Rockwell Automation's large Allen-Bradley installed base and is commonly run on engineering workstations and OPC servers, though most instances sit on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover.

Weakness
CWE-191
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Rockwell Automation RSLinx Classic

CISA flags four flaws (CVE-2026-9621/9622/9624/9625) in Rockwell RSLinx Classic 4.50 and below that can cause denial-of-service conditions; CVSS 8.6.

CISA published an ICS advisory covering four vulnerabilities in Rockwell Automation RSLinx Classic versions 4.50 and below. The integer overflow, underflow, and classic buffer overflow flaws (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) could let attackers cause denial-of-service conditions. The product is deployed worldwide, primarily in critical manufacturing.