CVE-2026-9624

8.7

Rockwell Automation · RSLinx Classic

Rockwell Automation RSLinx Classic is vulnerable to a denial of service attack via a crafted CIP packet, which triggers a service crash due to insufficient data length validation.

Executive summary

A critical denial of service vulnerability in Rockwell Automation RSLinx Classic allows unauthenticated remote attackers to crash the service, disrupting critical industrial communication processes.

Vulnerability

This vulnerability is caused by an integer underflow (CWE-191) resulting from insufficient validation of data lengths within Common Industrial Protocol (CIP) packets. The flaw is remotely exploitable by an unauthenticated attacker, requiring no user interaction.

Business impact

The ability for an unauthenticated attacker to remotely crash RSLinx Classic introduces significant operational risk. Because this software is essential for industrial communication, a service crash leads to immediate loss of visibility and control over automation hardware, resulting in unplanned downtime and potential safety hazards. With a CVSS score of 8.7, this high-severity vulnerability warrants immediate attention to prevent operational disruption.

Remediation

Immediate Action: Review the Rockwell Automation security advisory SD1794 to identify if a firmware or software update is available for your specific environment and apply it immediately.

Proactive Monitoring: Monitor industrial network traffic for malformed CIP packets and observe the RSLinx Classic service for unexpected crashes or restart cycles.

Compensating Controls: Restrict network access to the RSLinx Classic service by implementing strict firewall rules and network segmentation, ensuring only authorized engineering workstations can communicate with the affected systems.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the critical nature of industrial automation software, organizations should treat this vulnerability with high priority. Organizations must verify their current RSLinx Classic version and isolate affected systems from public or untrusted network segments until the vendor-supplied security update is applied.

More Rockwell Automation CVEs

Sources