Impact
A crafted CIP packet that is malformed can cause the RSLinx Classic service to crash, resulting in an outage that requires a restart. The vulnerability arises from improper handling of packet data and is classified as an integer overflow weakness. The impact is limited to the availability of the RSLinx Classic software: an attacker can force the service to stop, disrupting any processes that depend on real‑time data collection or device control.
Affected Systems
Rockwell Automation RSLinx Classic is affected, specifically versions 4.50 and earlier. The software’s common platform enumeration indicates that the flaw is present in all builds released up to and including 4.50.
Risk and Exploitability
With a CVSS score of 9.2 the flaw is considered critical. No EPSS score or KEV listing is available, but the lack of an exploitation probability does not reduce the inherent risk; the high severity and the ability to trigger the crash remotely through a malformed network packet make the vulnerability attractive to attackers in environments where RSLinx Classic is exposed.
OpenCVE Enrichment