CVE-2026-9622
8.7Rockwell · RSLinx Classic
A denial-of-service vulnerability in Rockwell RSLinx Classic allows unauthenticated attackers to crash the service by sending a crafted CIP packet to the Forward Close service.
Executive summary
Rockwell RSLinx Classic is vulnerable to a remote denial-of-service attack that can cause service disruption via a specially crafted CIP packet.
Vulnerability
This integer underflow vulnerability (CWE-191) exists within the Forward Close service of RSLinx Classic. The attack vector is network-based and requires no authentication or user interaction to trigger a service crash.
Business impact
The successful exploitation of this vulnerability results in an immediate denial-of-service condition, rendering the affected RSLinx Classic component unresponsive. Given the CVSS score of 8.7, this flaw poses a high risk to operational continuity, as it requires a manual restart of the service to restore functionality, potentially leading to significant downtime in industrial control environments.
Remediation
Immediate Action: Monitor the Rockwell Automation Trust Center for the release of security updates and apply them as soon as they become available for your specific deployment.
Proactive Monitoring: Implement network intrusion detection systems to identify and alert on unusual CIP packet traffic, specifically monitoring for anomalous requests directed at the Forward Close service.
Compensating Controls: Restrict network access to the RSLinx Classic service by utilizing firewalls or access control lists to ensure only authorized devices can communicate with the application.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a high risk to availability due to the ease with which an unauthenticated attacker can disrupt critical services. Administrators should prioritize identifying vulnerable instances within their network and applying vendor-supplied patches immediately upon their release to prevent potential operational outages.