{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/rslinx-classic-4.50/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rockwell_automation:rslinx_classic:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-9621"},{"id":"CVE-2026-9622"},{"id":"CVE-2026-9624"},{"id":"CVE-2026-9625"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["RSLinx Classic (\u003c=4.50)"],"_cs_severities":["medium"],"_cs_tags":["ics","ot","denial-of-service","vulnerability"],"_cs_type":"advisory","_cs_vendors":["Rockwell Automation"],"content_html":"\u003cp\u003eRockwell Automation RSLinx Classic versions 4.50 and earlier are affected by multiple memory-related vulnerabilities, specifically identified as CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, and CVE-2026-9625. These vulnerabilities stem from improper handling and insufficient validation of malformed or oversized Common Industrial Protocol (CIP) packets sent to the RSLinx Classic service.\u003c/p\u003e\n\u003cp\u003eWhen processed, these malformed packets can trigger integer overflows, underflows, or buffer overflows within the RSLinx service, resulting in an unrecoverable service crash. Successful exploitation results in a denial-of-service condition, necessitating a manual restart of the affected service to restore functionality. This is particularly concerning in Industrial Control System (ICS) environments where availability is critical for operational technology (OT) process monitoring and communication. Attackers can exploit these flaws remotely without authentication, targeting the Industrial Manufacturing sector.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities leads to a complete denial-of-service of the RSLinx Classic service. This prevents legitimate communication between industrial applications and field devices, potentially disrupting industrial control processes. Given the lack of authentication required, the impact is considered high in critical manufacturing environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of RSLinx Classic to version 4.60 or later to remediate CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, and CVE-2026-9625.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately feasible, implement firewall restrictions to limit access to the RSLinx Classic service (typically running over CIP/EtherNet/IP, port 44818) to only trusted engineering workstations or authorized communication sources.\u003c/li\u003e\n\u003cli\u003eConsult Rockwell Automation security best practices (A_ID/1085012) for hardening guidance in OT environments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-01T17:10:44Z","date_published":"2026-09-01T17:10:44Z","id":"https://feed.craftedsignal.io/briefs/2026-09-rockwell-rslinx-dos/","summary":"Multiple vulnerabilities in Rockwell Automation RSLinx Classic allow an unauthenticated remote attacker to cause a denial-of-service condition via specially crafted CIP packets.","title":"Denial of Service Vulnerabilities in Rockwell Automation RSLinx Classic","url":"https://feed.craftedsignal.io/briefs/2026-09-rockwell-rslinx-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - RSLinx Classic (\u003c=4.50)","version":"https://jsonfeed.org/version/1.1"}