Impact
A denial‑of‑service flaw exists in RSLinx Classic where an attacker can craft a CIP packet that bypasses insufficient data‑length validation. When the malformed packet is processed the RSLinx service crashes and must be manually restarted to recover, resulting in loss of connectivity to connected automation devices.
Affected Systems
The impacted product is Rockwell Automation's RSLinx Classic. Versions v4.50 and all prior releases are affected. The CPE taxonomy confirms the vulnerability applies to these product releases.
Risk and Exploitability
The CVSS score of 8.7 categorizes this flaw as High severity. No EPSS value is published, so the exploitation probability is uncertain. The flaw is not listed in the CISA KEV catalog. The likely attack vector is via a crafted CIP packet sent over the network to the RSLinx service; successful exploitation requires the attacker to send the packet to the affected system but no additional authentication is advertised or required in the description, so a local or network attacker could potentially cause the crash.
OpenCVE Enrichment