ZeroHour
Product

RSLinx Classic

1 mentions in 7 days · 3 in 30 days · 3 total · first seen · last

Timeline

ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws

September ICS Patch Tuesday brings critical fixes from Schneider Electric, Siemens, and Aveva, including CVSS 9.2 authentication flaw CVE-2026-3869 in Modicon M580 controllers.

Schneider Electric's September advisories include a critical authentication vulnerability, CVE-2026-3869 with a CVSS score of 9.2, in Modicon M580 and Modicon M580 Safety controllers, plus high-severity bugs in PowerLogic T300 and EcoStruxure IT Data Center Expert. Siemens published nine new advisories, four rated critical across Reyrolle 7SR5, Open Interface Services, Industrial Edge Management, and SIMOVE Fleetmanager and SIPLANT, and began rolling out fixes for CVE-2026-31431, a 7.8-rated Linux kernel flaw enabling root shell access. Aveva disclosed four flaws in Pipeline Integrity Monitor's PIMBoards, including a hardcoded encryption key and MD5-hashed passwords, plus an unsafe deserialization issue in Enterprise SCADA. Rockwell Automation separately issued nine advisories covering RSLinx Classic and multiple controller products.

Rockwell Automation security advisory (AV26-869)

Canada's Cyber Centre flags vulnerabilities across multiple Rockwell Automation ICS products including ControlLogix 5580 and RSLinx Classic.

Canadian Centre for Cyber Security advisory AV26-869, dated September 1, 2026, lists vulnerabilities in Rockwell Automation products: 1756-ENBT Module (all versions), ArmorStart LT (v2.001 and earlier), CompactLogix 5380 / ControlLogix 5580 (V33 and earlier plus several V34-V36 releases), and RSLinx Classic (V4.50 and earlier). It references Rockwell advisories SD1792, SD1794, SD1797, and SD1798 and urges users to apply updates as available.

Canadian Centre for Cyber Security · 14d agoAdvisory

Rockwell Automation RSLinx Classic

CISA flags four flaws (CVE-2026-9621/9622/9624/9625) in Rockwell RSLinx Classic 4.50 and below that can cause denial-of-service conditions; CVSS 8.6.

CISA published an ICS advisory covering four vulnerabilities in Rockwell Automation RSLinx Classic versions 4.50 and below. The integer overflow, underflow, and classic buffer overflow flaws (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) could let attackers cause denial-of-service conditions. The product is deployed worldwide, primarily in critical manufacturing.

Related CVEs

  • Local Privilege Escalation (Copy Fail) in Linux Kernel algif_aead Interface
    CVE-2026-31431 ('Copy Fail') is an incorrect resource transfer between spheres (CWE-669/CWE-1288) in the Linux kernel's algif_aead implementation of the AF_ALG userspace crypto interface, introduced roughly nine years ago (around 2017, per public reporting) when commit 72548b093ee3 switched AEAD operations to in-place handling even though the source and destination buffers come from different mappings. A local, unprivileged user can trigger the flaw by performing AEAD operations through the AF_ALG socket interface, causing the kernel to mishandle the copy of ciphertext and associated data. Successful exploitation provides a reliable local privilege escalation to root (C:H/I:H/A:H per the CVSS vector). Nearly every major Linux distribution and enterprise platform is exposed, including the kernel itself, Red Hat Enterprise Linux (including AUS, EUS, TUS and Update Services for SAP Solutions), OpenShift Container Platform, Amazon Linux, Ubuntu, Debian, openSUSE Leap, SUSE CaaS Platform, NixOS, and Linux-based products from Arista and Siemens. The flaw has public proof-of-concept code, a 99.9% EPSS score, and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-05-01, indicating exploitation in the wild (ransomware use is unknown).
    · Linux kernel (algif_aead / AF_ALG crypto interface) · Red Hat Enterprise Linux (including AUS, EUS, TUS, and Update Services for SAP Solutions) KEV PoC ×5mass
  • Flawed Authentication Algorithm in Schneider Electric PLC Enables Full Compromise
    CVE-2026-3869 is a critical (CVSS 4.0 score 9.2) incorrect implementation of an authentication algorithm (CWE-303) in a Schneider Electric programmable logic controller (PLC), disclosed and patched as part of Schneider Electric's ICS Patch Tuesday release. The flaw is reachable over the network with no privileges or user interaction required, but it carries elevated attack requirements: it comes into play when the PLC is running an application project with a lower application level, which is the configuration precondition for exploitation. An attacker who meets those conditions can defeat the controller's authentication mechanism and cause a complete loss of confidentiality, integrity and availability of the PLC (VC:H/VI:H/VA:H), meaning they could read, modify or disrupt the running control process. Affected users are operators of the impacted Schneider Electric PLC line; the available data does not name the specific model or firmware versions, so operators should confirm their exposure against the official Schneider notification. No public proof-of-concept is known and the flaw is not listed in CISA's KEV, with no reports of exploitation in the wild to date.
    · Schneider Electric PLC (specific model line not identified in the available data)large
  • Unauthenticated Remote DoS in Rockwell Automation RSLinx Classic
    CVE-2026-9621 is a critical-severity (CVSS 4.0: 9.2) denial-of-service flaw in Rockwell Automation's RSLinx Classic, caused by improper handling of malformed packets and classified under CWE-190 (integer overflow/wraparound). A remote, unauthenticated attacker can trigger the condition by sending a specially crafted CIP packet to the service over the network. The impact is availability-only: the RSLinx Classic service crashes and must be manually restarted to recover, with no confidentiality or integrity impact per the CVSS vector, though the high subsequent-system (SA:H) score indicates downstream OT systems and processes can be disrupted. Any installation running the RSLinx Classic service where the CIP endpoint is network-reachable is affected, most typically plant-floor or engineering workstations. There is no public proof-of-concept, no CISA KEV listing, and EPSS is low (0.3%), so active exploitation is currently considered unlikely or unobserved.
    · Rockwell Automation RSLinx Classiclarge
  • Denial-of-Service in Rockwell Automation RSLinx Classic via Oversized CIP Packet
    CVE-2026-9625 is a denial-of-service flaw in Rockwell Automation's RSLinx Classic industrial communications software, caused by improper handling of input sizes (CWE-120) when parsing CIP (Common Industrial Protocol) messages. An attacker who can reach the RSLinx Classic service over a network can send a single crafted CIP packet containing an oversized embedded message request, which crashes the service. The impact is availability-only: the RSLinx Classic service stops and must be manually restarted to recover, with no evidence of code execution or data compromise (CVSS 4.0 scores availability impact High and all other impacts None). Any organization running RSLinx Classic on workstations or servers that connect operations or maintenance software to Allen-Bradley/Rockwell controllers is potentially affected, particularly where the service is reachable from enterprise or internet-facing networks. As of this writing there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates roughly a 0.3% probability of exploitation within 30 days.
    · Rockwell Automation RSLinx Classiclarge
  • Remote Denial-of-Service in Rockwell Automation RSLinx Classic via Crafted CIP Packet
    CVE-2026-9624 is a denial-of-service flaw in Rockwell Automation's RSLinx Classic industrial communications software: the service fails to properly validate the data length field of incoming CIP packets (CWE-191), so a single crafted packet can crash it. An attacker with network access to the RSLinx service can trigger the crash remotely, with no privileges or user interaction required. The impact is availability-only — the RSLinx service stops and must be manually restarted, interrupting PC-to-controller communications, data collection, or monitoring that depends on it; confidentiality and integrity are unaffected. Any installation running RSLinx Classic where the service is reachable over the network (e.g., engineering workstations or servers in OT/manufacturing environments) is potentially affected. There is currently no known exploitation: the flaw is not in CISA's KEV catalog, no public proof-of-concept exists, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.
    · Rockwell Automation RSLinx Classiclarge
  • Unauthenticated Denial-of-Service in Rockwell Automation RSLinx Classic
    CVE-2026-9622 is a remotely exploitable denial-of-service flaw in Rockwell Automation RSLinx Classic, an industrial communications and OPC server product used alongside Allen-Bradley controllers. An attacker with network reachability to the service can send a crafted CIP (Common Industrial Protocol) packet targeting the Forward Close service, which the software mishandles due to an integer coercion error (CWE-191). The result is a crash of the RSLinx Classic service, and a manual restart of the service is required to restore operations; there is no confidentiality or integrity impact and no indication of code execution. The CVSS 4.0 score of 8.7 (High) reflects unauthenticated network access with a high availability impact on the vulnerable system. No public proof-of-concept exists, the issue is not in CISA KEV, and EPSS estimates the 30-day exploitation probability at about 0.3 percent, so no exploitation is currently known.
    · Rockwell Automation RSLinx Classiclarge

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.