Impact
A crafted Common Industrial Protocol packet containing an oversized embedded message can trigger a crash of the RSLinx Classic service, leading to unavailability of the application until it is manually restarted. This vulnerability is a classic overflow type weakness identified as CWE‑120, where improper handling of packet size leads to a service crash regardless of data content. The impact is purely availability loss rather than data leakage or credential compromise.
Affected Systems
The vulnerability affects RSLinx Classic installations run by Rockwell Automation, specifically versions 4.50 and all prior releases. Systems running older builds of the software without any subsequent patch or update are within scope.
Risk and Exploitability
With a CVSS score of 8.7 the weakness is considered high severity. EPSS data is not available, so the likelihood of exploitation in the wild cannot be quantified from the CVE record. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely remote over the network: an adversary could send a malicious CIP packet to the RSLinx Classic service from an untrusted source or from within the local network if access controls are weak. Successful exploitation would cause the service to crash, requiring a restart and causing a denial of service for users.
OpenCVE Enrichment