Description
A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover
Published: 2026-09-01
Score: 9.2 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A crafted CIP packet that is malformed can cause the RSLinx Classic service to crash, resulting in an outage that requires a restart. The vulnerability arises from improper handling of packet data and is classified as an integer overflow weakness. The impact is limited to the availability of the RSLinx Classic software: an attacker can force the service to stop, disrupting any processes that depend on real‑time data collection or device control.

Affected Systems

Rockwell Automation RSLinx Classic is affected, specifically versions 4.50 and earlier. The software’s common platform enumeration indicates that the flaw is present in all builds released up to and including 4.50.

Risk and Exploitability

With a CVSS score of 9.2 the flaw is considered critical. No EPSS score or KEV listing is available, but the lack of an exploitation probability does not reduce the inherent risk; the high severity and the ability to trigger the crash remotely through a malformed network packet make the vulnerability attractive to attackers in environments where RSLinx Classic is exposed.

Generated by OpenCVE AI on September 1, 2026 at 15:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Follow the vendor’s security advisory and install the latest RSLinx Classic release (or the applicable patch) to eliminate the integer‑overflow code path.
  • If a patch is not immediately available, limit inbound traffic on the CIP port (default 44818) to known, trusted IP addresses or use a firewall rule to drop malformed packets.
  • Set up monitoring or alerts for unexpected RSLinx Classic service restarts so that any abrupt outages can be investigated promptly.

Generated by OpenCVE AI on September 1, 2026 at 15:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation rslinx Classic
Vendors & Products Rockwellautomation
Rockwellautomation rslinx Classic
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover
Title RSLinx Classic® - Multiple Vulnerabilities
First Time appeared Rockwell Automation
Rockwell Automation rslinx Classic
Weaknesses CWE-190
CPEs cpe:2.3:a:rockwell_automation:rslinx_classic_:v4.50_and_prior:*:*:*:*:*:*:*
Vendors & Products Rockwell Automation
Rockwell Automation rslinx Classic
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


Subscriptions

Rockwell Automation Rslinx Classic
Rockwellautomation Rslinx Classic
cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-09-01T15:46:15.077Z

Reserved: 2026-05-26T17:18:12.101Z

Link: CVE-2026-9621

cve-icon Vulnrichment

Updated: 2026-09-01T15:46:07.630Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T14:17:49.377

Modified: 2026-09-01T20:50:01.960

Link: CVE-2026-9621

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T15:30:04Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound