Denial of Service Vulnerabilities in Rockwell Automation RSLinx Classic
Multiple vulnerabilities in Rockwell Automation RSLinx Classic allow an unauthenticated remote attacker to cause a denial-of-service condition via specially crafted CIP packets.
CVE search metadata
CVE search record: CVE-2026-9621. KEV: no. Product: RSLinx Classic (<=4.50). Brief: Denial of Service Vulnerabilities in Rockwell Automation RSLinx Classic. Brief link: https://feed.craftedsignal.io/briefs/2026-09-rockwell-rslinx-dos/
CVE search record: CVE-2026-9622. KEV: no. Product: RSLinx Classic (<=4.50). Brief: Denial of Service Vulnerabilities in Rockwell Automation RSLinx Classic. Brief link: https://feed.craftedsignal.io/briefs/2026-09-rockwell-rslinx-dos/
CVE search record: CVE-2026-9624. KEV: no. Product: RSLinx Classic (<=4.50). Brief: Denial of Service Vulnerabilities in Rockwell Automation RSLinx Classic. Brief link: https://feed.craftedsignal.io/briefs/2026-09-rockwell-rslinx-dos/
CVE search record: CVE-2026-9625. KEV: no. Product: RSLinx Classic (<=4.50). Brief: Denial of Service Vulnerabilities in Rockwell Automation RSLinx Classic. Brief link: https://feed.craftedsignal.io/briefs/2026-09-rockwell-rslinx-dos/
Rockwell Automation RSLinx Classic versions 4.50 and earlier are affected by multiple memory-related vulnerabilities, specifically identified as CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, and CVE-2026-9625. These vulnerabilities stem from improper handling and insufficient validation of malformed or oversized Common Industrial Protocol (CIP) packets sent to the RSLinx Classic service.
When processed, these malformed packets can trigger integer overflows, underflows, or buffer overflows within the RSLinx service, resulting in an unrecoverable service crash. Successful exploitation results in a denial-of-service condition, necessitating a manual restart of the affected service to restore functionality. This is particularly concerning in Industrial Control System (ICS) environments where availability is critical for operational technology (OT) process monitoring and communication. Attackers can exploit these flaws remotely without authentication, targeting the Industrial Manufacturing sector.
Impact
Successful exploitation of these vulnerabilities leads to a complete denial-of-service of the RSLinx Classic service. This prevents legitimate communication between industrial applications and field devices, potentially disrupting industrial control processes. Given the lack of authentication required, the impact is considered high in critical manufacturing environments.
Recommendation
- Upgrade all instances of RSLinx Classic to version 4.60 or later to remediate CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, and CVE-2026-9625.
- If upgrading is not immediately feasible, implement firewall restrictions to limit access to the RSLinx Classic service (typically running over CIP/EtherNet/IP, port 44818) to only trusted engineering workstations or authorized communication sources.
- Consult Rockwell Automation security best practices (A_ID/1085012) for hardening guidance in OT environments.
Immediate actions
Upgrade RSLinx Classic to 4.60 or later
Mitigations
Restrict access to CIP port 44818 at the network perimeter
CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625