ZeroHour
CISA Advisoriespublished ()ingested CISA

Rockwell Automation RSLinx Classic

AI summary · glm-5.3-flash

CISA flags four flaws (CVE-2026-9621/9622/9624/9625) in Rockwell RSLinx Classic 4.50 and below that can cause denial-of-service conditions; CVSS 8.6.

CISA published an ICS advisory covering four vulnerabilities in Rockwell Automation RSLinx Classic versions 4.50 and below. The integer overflow, underflow, and classic buffer overflow flaws (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) could let attackers cause denial-of-service conditions. The product is deployed worldwide, primarily in critical manufacturing.

  • Four flaws can trigger denial-of-service conditions
  • RSLinx Classic 4.50 and earlier affected
  • CVSS v3 base score of 8.6
  • Widely deployed in critical manufacturing worldwide

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-9621
Unauthenticated Remote DoS in Rockwell Automation RSLinx Classic

CVE-2026-9621 is a critical-severity (CVSS 4.0: 9.2) denial-of-service flaw in Rockwell Automation's RSLinx Classic, caused by improper handling of malformed packets and classified under CWE-190 (integer overflow/wraparound). A remote, unauthenticated attacker can trigger the condition by sending a specially crafted CIP packet to the service over the network. The impact is availability-only: the RSLinx Classic service crashes and must be manually restarted to recover, with no confidentiality or integrity impact per the CVSS vector, though the high subsequent-system (SA:H) score indicates downstream OT systems and processes can be disrupted. Any installation running the RSLinx Classic service where the CIP endpoint is network-reachable is affected, most typically plant-floor or engineering workstations. There is no public proof-of-concept, no CISA KEV listing, and EPSS is low (0.3%), so active exploitation is currently considered unlikely or unobserved.

Do: Inventory hosts running RSLinx Classic and check Rockwell Automation's security advisory for the affected versions and fixed releases before patching, since no version numbers are provided in this data. Until patched, restrict network access to the RSLinx Classic service and its CIP endpoints to trusted hosts only. Monitor the service for crashes and be prepared to restart it to restore communications to downstream devices.

9.2<1%
  • Rockwell Automation RSLinx Classic
large≈ tens of thousands of installations at industrial sites (deployment-pattern estimate)
CVE-2026-9622
Unauthenticated Denial-of-Service in Rockwell Automation RSLinx Classic

CVE-2026-9622 is a remotely exploitable denial-of-service flaw in Rockwell Automation RSLinx Classic, an industrial communications and OPC server product used alongside Allen-Bradley controllers. An attacker with network reachability to the service can send a crafted CIP (Common Industrial Protocol) packet targeting the Forward Close service, which the software mishandles due to an integer coercion error (CWE-191). The result is a crash of the RSLinx Classic service, and a manual restart of the service is required to restore operations; there is no confidentiality or integrity impact and no indication of code execution. The CVSS 4.0 score of 8.7 (High) reflects unauthenticated network access with a high availability impact on the vulnerable system. No public proof-of-concept exists, the issue is not in CISA KEV, and EPSS estimates the 30-day exploitation probability at about 0.3 percent, so no exploitation is currently known.

Do: Monitor Rockwell Automation's security advisory for CVE-2026-9622 and upgrade RSLinx Classic to a patched release once one is published, since no fixed version is given in the available data. In the meantime, restrict network access to the CIP/EtherNet-IP service used by RSLinx (commonly TCP/44818 and related EtherNet/IP traffic) from untrusted networks and keep it segmented from corporate or internet-facing zones. Ensure staff know the recovery procedure (restart the RSLinx Classic service) and monitor for unexpected service crashes as an indicator of probing or exploitation.

8.7<1%
  • Rockwell Automation RSLinx Classic
largeon the order of 100,000+ installations across tens of thousands of industrial sites (estimate)
CVE-2026-9624
Remote Denial-of-Service in Rockwell Automation RSLinx Classic via Crafted CIP Packet

CVE-2026-9624 is a denial-of-service flaw in Rockwell Automation's RSLinx Classic industrial communications software: the service fails to properly validate the data length field of incoming CIP packets (CWE-191), so a single crafted packet can crash it. An attacker with network access to the RSLinx service can trigger the crash remotely, with no privileges or user interaction required. The impact is availability-only — the RSLinx service stops and must be manually restarted, interrupting PC-to-controller communications, data collection, or monitoring that depends on it; confidentiality and integrity are unaffected. Any installation running RSLinx Classic where the service is reachable over the network (e.g., engineering workstations or servers in OT/manufacturing environments) is potentially affected. There is currently no known exploitation: the flaw is not in CISA's KEV catalog, no public proof-of-concept exists, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.

Do: Track Rockwell Automation's advisory ([email protected] is the CNA) for the definitive list of affected versions and patched releases, and upgrade as soon as a fix is available — no version details are yet in the public data. In the interim, restrict network access to the RSLinx Classic service by allowing CIP/EtherNet/IP traffic only from trusted hosts (firewall rules, ACLs, or OT network segmentation), since the attack vector is network-based with no authentication required. Monitor hosts running RSLinx for unexpected service crashes and have a documented restart procedure ready, as recovery requires restarting the service.

8.7<1%
  • Rockwell Automation RSLinx Classic
largelikely on the order of tens of thousands to low hundreds of thousands of installations worldwide; exact count unknown
CVE-2026-9625
Denial-of-Service in Rockwell Automation RSLinx Classic via Oversized CIP Packet

CVE-2026-9625 is a denial-of-service flaw in Rockwell Automation's RSLinx Classic industrial communications software, caused by improper handling of input sizes (CWE-120) when parsing CIP (Common Industrial Protocol) messages. An attacker who can reach the RSLinx Classic service over a network can send a single crafted CIP packet containing an oversized embedded message request, which crashes the service. The impact is availability-only: the RSLinx Classic service stops and must be manually restarted to recover, with no evidence of code execution or data compromise (CVSS 4.0 scores availability impact High and all other impacts None). Any organization running RSLinx Classic on workstations or servers that connect operations or maintenance software to Allen-Bradley/Rockwell controllers is potentially affected, particularly where the service is reachable from enterprise or internet-facing networks. As of this writing there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates roughly a 0.3% probability of exploitation within 30 days.

Do: Check Rockwell Automation's security advisory for CVE-2026-9625 for the affected version list and patched release, and apply the update when available. Until patched, restrict network access to hosts running the RSLinx Classic service and its EtherNet/IP CIP ports (commonly TCP/UDP 44818) from untrusted networks, and monitor for unexpected service crashes. If the service crashes, restart the RSLinx Classic service to restore operations.

8.7<1%
  • Rockwell Automation RSLinx Classic
largeapproximately 100,000 to 1,000,000 installed workstations/servers (installed base estimate, not internet-exposed device count)
Full article

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation RSLinx Classic are affected: RSLinx Classic <=4.50 (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) CVSS Vendor Equipment Vulnerabilities v3 8.6 Rockwell Automation Rockwell Automation RSLinx Classic Integer Overflow or Wraparound, Integer Underflow (Wrap or Wraparound), Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United…

This source does not provide full text. Read it at cisa.gov.