CVE-2026-9624
8.7Rockwell Automation · RSLinx Classic
Rockwell Automation RSLinx Classic is vulnerable to a denial of service attack via a crafted CIP packet, which triggers a service crash due to insufficient data length validation.
Executive summary
A critical denial of service vulnerability in Rockwell Automation RSLinx Classic allows unauthenticated remote attackers to crash the service, disrupting critical industrial communication processes.
Vulnerability
This vulnerability is caused by an integer underflow (CWE-191) resulting from insufficient validation of data lengths within Common Industrial Protocol (CIP) packets. The flaw is remotely exploitable by an unauthenticated attacker, requiring no user interaction.
Business impact
The ability for an unauthenticated attacker to remotely crash RSLinx Classic introduces significant operational risk. Because this software is essential for industrial communication, a service crash leads to immediate loss of visibility and control over automation hardware, resulting in unplanned downtime and potential safety hazards. With a CVSS score of 8.7, this high-severity vulnerability warrants immediate attention to prevent operational disruption.
Remediation
Immediate Action: Review the Rockwell Automation security advisory SD1794 to identify if a firmware or software update is available for your specific environment and apply it immediately.
Proactive Monitoring: Monitor industrial network traffic for malformed CIP packets and observe the RSLinx Classic service for unexpected crashes or restart cycles.
Compensating Controls: Restrict network access to the RSLinx Classic service by implementing strict firewall rules and network segmentation, ensuring only authorized engineering workstations can communicate with the affected systems.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the critical nature of industrial automation software, organizations should treat this vulnerability with high priority. Organizations must verify their current RSLinx Classic version and isolate affected systems from public or untrusted network segments until the vendor-supplied security update is applied.