CVE-2026-9621
9.2Rockwell Automation · RSLinx Classic
A denial of service vulnerability in Rockwell Automation RSLinx Classic allows unauthenticated attackers to crash the service via a malformed CIP packet.
Executive summary
A critical vulnerability in Rockwell Automation RSLinx Classic enables unauthenticated remote attackers to trigger a denial of service condition, potentially disrupting industrial operations.
Vulnerability
This vulnerability is caused by an integer overflow or wraparound condition (CWE-190) that occurs when the software processes malformed Common Industrial Protocol (CIP) packets. Because the vulnerability is accessible via the network without authentication (PR:N, UI:N), an attacker can remotely cause the service to crash.
Business impact
The exploitation of this flaw leads to a complete service disruption of the RSLinx Classic application, which is a critical component for communication between industrial control systems. Given the CVSS score of 9.2, this vulnerability represents a severe operational risk that could result in significant downtime for manufacturing or process control environments.
Remediation
Immediate Action: Update Rockwell Automation RSLinx Classic to the latest version provided by the vendor in the official security advisory.
Proactive Monitoring: Monitor network traffic for anomalous CIP packets and review system logs for recurring RSLinx service crashes or unexpected process terminations.
Compensating Controls: Implement network segmentation to restrict access to the RSLinx service to authorized hosts only and deploy industrial firewalls capable of inspecting and filtering malformed CIP traffic.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the critical nature of this vulnerability and the potential for operational impact in industrial settings, administrators should prioritize patching immediately. If patching is not immediately feasible, network-level isolation of the affected RSLinx instances is strongly recommended to minimize the attack surface until the update can be applied.