ZeroHour

CVE-2026-9625

large

Denial-of-Service in Rockwell Automation RSLinx Classic via Oversized CIP Packet

CVSS 4.0
8.7 high
EPSS
<1%p24
Published
()
Modified
AI analysis

CVE-2026-9625 is a denial-of-service flaw in Rockwell Automation's RSLinx Classic industrial communications software, caused by improper handling of input sizes (CWE-120) when parsing CIP (Common Industrial Protocol) messages. An attacker who can reach the RSLinx Classic service over a network can send a single crafted CIP packet containing an oversized embedded message request, which crashes the service. The impact is availability-only: the RSLinx Classic service stops and must be manually restarted to recover, with no evidence of code execution or data compromise (CVSS 4.0 scores availability impact High and all other impacts None). Any organization running RSLinx Classic on workstations or servers that connect operations or maintenance software to Allen-Bradley/Rockwell controllers is potentially affected, particularly where the service is reachable from enterprise or internet-facing networks. As of this writing there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates roughly a 0.3% probability of exploitation within 30 days.

What to do: Check Rockwell Automation's security advisory for CVE-2026-9625 for the affected version list and patched release, and apply the update when available. Until patched, restrict network access to hosts running the RSLinx Classic service and its EtherNet/IP CIP ports (commonly TCP/UDP 44818) from untrusted networks, and monitor for unexpected service crashes. If the service crashes, restart the RSLinx Classic service to restore operations.

Affected
Rockwell Automation RSLinx Classic
Estimated exposure
largeapproximately 100,000 to 1,000,000 installed workstations/servers (installed base estimate, not internet-exposed device count) — RSLinx Classic is Rockwell Automation's widely deployed legacy EtherNet/IP communications software, historically bundled with engineering and maintenance workflows across Rockwell's large North American PLC installed base, implying an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover.

Weakness
CWE-120
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Rockwell Automation RSLinx Classic

CISA flags four flaws (CVE-2026-9621/9622/9624/9625) in Rockwell RSLinx Classic 4.50 and below that can cause denial-of-service conditions; CVSS 8.6.

CISA published an ICS advisory covering four vulnerabilities in Rockwell Automation RSLinx Classic versions 4.50 and below. The integer overflow, underflow, and classic buffer overflow flaws (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) could let attackers cause denial-of-service conditions. The product is deployed worldwide, primarily in critical manufacturing.