ZeroHour

CVE-2026-9624

large

Remote Denial-of-Service in Rockwell Automation RSLinx Classic via Crafted CIP Packet

CVSS 4.0
8.7 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-9624 is a denial-of-service flaw in Rockwell Automation's RSLinx Classic industrial communications software: the service fails to properly validate the data length field of incoming CIP packets (CWE-191), so a single crafted packet can crash it. An attacker with network access to the RSLinx service can trigger the crash remotely, with no privileges or user interaction required. The impact is availability-only — the RSLinx service stops and must be manually restarted, interrupting PC-to-controller communications, data collection, or monitoring that depends on it; confidentiality and integrity are unaffected. Any installation running RSLinx Classic where the service is reachable over the network (e.g., engineering workstations or servers in OT/manufacturing environments) is potentially affected. There is currently no known exploitation: the flaw is not in CISA's KEV catalog, no public proof-of-concept exists, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.

What to do: Track Rockwell Automation's advisory ([email protected] is the CNA) for the definitive list of affected versions and patched releases, and upgrade as soon as a fix is available — no version details are yet in the public data. In the interim, restrict network access to the RSLinx Classic service by allowing CIP/EtherNet/IP traffic only from trusted hosts (firewall rules, ACLs, or OT network segmentation), since the attack vector is network-based with no authentication required. Monitor hosts running RSLinx for unexpected service crashes and have a documented restart procedure ready, as recovery requires restarting the service.

Affected
Rockwell Automation RSLinx Classic
Estimated exposure
largelikely on the order of tens of thousands to low hundreds of thousands of installations worldwide; exact count unknown — RSLinx Classic is the standard Rockwell component used on engineering workstations and servers to communicate with Allen-Bradley controllers across Rockwell's large installed manufacturing base, but no public install counts exist, and only…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length validation, requiring a restart of the service to recover.

Weakness
CWE-191
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Rockwell Automation RSLinx Classic

CISA flags four flaws (CVE-2026-9621/9622/9624/9625) in Rockwell RSLinx Classic 4.50 and below that can cause denial-of-service conditions; CVSS 8.6.

CISA published an ICS advisory covering four vulnerabilities in Rockwell Automation RSLinx Classic versions 4.50 and below. The integer overflow, underflow, and classic buffer overflow flaws (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) could let attackers cause denial-of-service conditions. The product is deployed worldwide, primarily in critical manufacturing.