<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:rockwell_automation:rslinx_classic:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3arockwell_automationrslinx_classic/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 01 Sep 2026 17:10:44 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3arockwell_automationrslinx_classic/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service Vulnerabilities in Rockwell Automation RSLinx Classic</title><link>https://feed.craftedsignal.io/briefs/2026-09-rockwell-rslinx-dos/</link><pubDate>Tue, 01 Sep 2026 17:10:44 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-rockwell-rslinx-dos/</guid><description>Multiple vulnerabilities in Rockwell Automation RSLinx Classic allow an unauthenticated remote attacker to cause a denial-of-service condition via specially crafted CIP packets.</description><content:encoded><![CDATA[<p>Rockwell Automation RSLinx Classic versions 4.50 and earlier are affected by multiple memory-related vulnerabilities, specifically identified as CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, and CVE-2026-9625. These vulnerabilities stem from improper handling and insufficient validation of malformed or oversized Common Industrial Protocol (CIP) packets sent to the RSLinx Classic service.</p>
<p>When processed, these malformed packets can trigger integer overflows, underflows, or buffer overflows within the RSLinx service, resulting in an unrecoverable service crash. Successful exploitation results in a denial-of-service condition, necessitating a manual restart of the affected service to restore functionality. This is particularly concerning in Industrial Control System (ICS) environments where availability is critical for operational technology (OT) process monitoring and communication. Attackers can exploit these flaws remotely without authentication, targeting the Industrial Manufacturing sector.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities leads to a complete denial-of-service of the RSLinx Classic service. This prevents legitimate communication between industrial applications and field devices, potentially disrupting industrial control processes. Given the lack of authentication required, the impact is considered high in critical manufacturing environments.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all instances of RSLinx Classic to version 4.60 or later to remediate CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, and CVE-2026-9625.</li>
<li>If upgrading is not immediately feasible, implement firewall restrictions to limit access to the RSLinx Classic service (typically running over CIP/EtherNet/IP, port 44818) to only trusted engineering workstations or authorized communication sources.</li>
<li>Consult Rockwell Automation security best practices (A_ID/1085012) for hardening guidance in OT environments.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>ics</category><category>ot</category><category>denial-of-service</category><category>vulnerability</category></item></channel></rss>