CVE-2026-9625

8.7

Rockwell Automation · RSLinx Classic

A buffer overflow in Rockwell Automation RSLinx Classic allows unauthenticated remote attackers to trigger a denial-of-service condition via a crafted CIP packet.

Executive summary

A critical denial-of-service vulnerability in Rockwell Automation RSLinx Classic allows unauthenticated remote attackers to crash the service by sending a specially crafted CIP packet.

Vulnerability

The vulnerability is a buffer overflow (CWE-120) triggered when the application processes a crafted CIP packet containing an oversized embedded message request. This flaw is exploitable by unauthenticated remote attackers without requiring user interaction.

Business impact

The exploitation of this vulnerability results in the disruption of industrial communication services, leading to potential operational downtime. With a CVSS score of 8.7, this high-severity flaw poses a significant threat to availability, as the service requires manual intervention and a restart to recover from the crash.

Remediation

Immediate Action: Monitor the Rockwell Automation Trust Center for the release of an official security update and apply it to all affected RSLinx Classic installations immediately.

Proactive Monitoring: Implement network traffic analysis to detect anomalous CIP packets or unexpected spikes in service restarts that may indicate attempted exploitation.

Compensating Controls: Utilize industrial firewalls or deep packet inspection (DPI) capable network appliances to restrict CIP traffic to trusted sources and block malformed packets.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the potential for operational impact in industrial environments, organizations should prioritize restricting network access to the RSLinx Classic service. Ensure that all systems are prepared for patching as soon as the vendor releases the necessary firmware or software update.

More Rockwell Automation CVEs

Sources