Remote Denial-of-Service in Rockwell Automation RSLinx Classic via Crafted CIP Packet
AI analysis
CVE-2026-9624 is a denial-of-service flaw in Rockwell Automation's RSLinx Classic industrial communications software: the service fails to properly validate the data length field of incoming CIP packets (CWE-191), so a single crafted packet can crash it. An attacker with network access to the RSLinx service can trigger the crash remotely, with no privileges or user interaction required. The impact is availability-only — the RSLinx service stops and must be manually restarted, interrupting PC-to-controller communications, data collection, or monitoring that depends on it; confidentiality and integrity are unaffected. Any installation running RSLinx Classic where the service is reachable over the network (e.g., engineering workstations or servers in OT/manufacturing environments) is potentially affected. There is currently no known exploitation: the flaw is not in CISA's KEV catalog, no public proof-of-concept exists, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.
What to do: Track Rockwell Automation's advisory ([email protected] is the CNA) for the definitive list of affected versions and patched releases, and upgrade as soon as a fix is available — no version details are yet in the public data. In the interim, restrict network access to the RSLinx Classic service by allowing CIP/EtherNet/IP traffic only from trusted hosts (firewall rules, ACLs, or OT network segmentation), since the attack vector is network-based with no authentication required. Monitor hosts running RSLinx for unexpected service crashes and have a documented restart procedure ready, as recovery requires restarting the service.
Affected
| Rockwell Automation RSLinx Classic | — |
Estimated exposure
largelikely on the order of tens of thousands to low hundreds of thousands of installations worldwide; exact count unknown — RSLinx Classic is the standard Rockwell component used on engineering workstations and servers to communicate with Allen-Bradley controllers across Rockwell's large installed manufacturing base, but no public install counts exist, and only…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length validation, requiring a restart of the service to recover.