Rockwell Automation RSLinx Classic (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624 +1 more)
Rockwell Automation RSLinx Classic versions 4.50 and earlier contain four network-exploitable denial-of-service vulnerabilities (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625). These flaws stem from integer overflows, underflows, and buffer overflows in the handling of crafted CIP packets, allowing an unauthenticated remote attacker to crash the service. A fix is available in version 4.60.
- cveCVE-2026-9621A denial-of-service condition occurs due to an integer overflow when handling a malformed CIP packet, causing the service to crash.
- cveCVE-2026-9622A denial-of-service condition occurs due to an integer underflow when a crafted CIP packet targets the Forward Close service, causing the service to crash.
- cveCVE-2026-9624A denial-of-service condition occurs due to an integer underflow caused by insufficient data length validation in a crafted CIP packet, causing the service to crash.
- cveCVE-2026-9625A denial-of-service condition occurs due to a buffer overflow when handling a crafted CIP packet with an oversized embedded message request, causing the service to crash.
Detection / Hunteropenrouter
What Happened
Security researchers found four flaws in Rockwell Automation's RSLinx Classic software (used in industrial control systems) that could let an attacker crash the program over a network. Anyone using versions 4.50 or older is affected. If exploited, these flaws could disrupt manufacturing processes that rely on this software. Organizations should update to version 4.60 immediately or follow network security best practices to protect their systems.
Key Takeaways
- Four denial-of-service vulnerabilities (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) affect Rockwell Automation RSLinx Classic versions 4.50 and earlier.
- The flaws stem from integer overflows, integer underflows, and buffer overflows in the handling of crafted CIP packets.
- Successful exploitation requires no privileges or user interaction and can be executed over the network.
- A vendor fix is available in RSLinx Classic version 4.60.
- CISA recommends minimizing network exposure for control system devices and isolating them from the internet.
Affected Systems
- Rockwell Automation RSLinx Classic <= 4.50
Vulnerabilities (CVEs)
| CVE | Product | Severity | Description |
|---|---|---|---|
| CVE-2026-9621 | Rockwell Automation RSLinx Classic | High | A denial-of-service condition occurs due to an integer overflow when handling a malformed CIP packet, causing the service to crash. |
| CVE-2026-9622 | Rockwell Automation RSLinx Classic | High | A denial-of-service condition occurs due to an integer underflow when a crafted CIP packet targets the Forward Close service, causing the service to crash. |
| CVE-2026-9624 | Rockwell Automation RSLinx Classic | High | A denial-of-service condition occurs due to an integer underflow caused by insufficient data length validation in a crafted CIP packet, causing the service to crash. |
| CVE-2026-9625 | Rockwell Automation RSLinx Classic | High | A denial-of-service condition occurs due to a buffer overflow when handling a crafted CIP packet with an oversized embedded message request, causing the service to crash. |
Attack Chain
- Initial Access: Attacker sends crafted CIP packets over the network to the RSLinx Classic service.
- Exploitation: Malformed packet triggers integer overflow, integer underflow, or buffer overflow.
- Impact: RSLinx Classic service crashes, causing a denial-of-service condition requiring manual restart.
Detection Availability
- YARA Rules: No
- Sigma Rules: No
- Snort/Suricata Rules: No
- KQL Queries: No
- Splunk SPL Queries: No
- EQL Queries: No
- Other Detection Logic: No
No detection rules are provided in the advisory. The article provides remediation and mitigation steps instead of detection logic.
Detection Engineering Assessment
| Dimension | Rating | Rationale |
|---|---|---|
| EDR Visibility | Low | Industrial control systems like those running RSLinx Classic often lack standard EDR agents, limiting process-level visibility. |
| Network Visibility | High | The vulnerabilities are exploited via crafted CIP packets over the network, which can be detected by network monitoring tools or IDS. |
| Detection Difficulty | Moderate | Detection requires parsing industrial protocol payloads (CIP) for malformed or oversized packets, which may require specialized ICS monitoring tools. |
Required Log Sources
- Network flow logs
- ICS firewall logs
- CIP protocol analyzer logs
Hunting Hypotheses
| Hypothesis | Telemetry | ATT&CK Stage | FP Risk |
|---|---|---|---|
| Hunt for network traffic containing malformed CIP packets targeting RSLinx Classic services. | Network packet captures, ICS-specific IDS logs | Initial Access | Low - malformed CIP packets are abnormal in operational environments. |
Control Gaps
- Standard IT endpoint detection may not cover ICS protocols like CIP.
- Legacy ICS devices may lack endpoint detection capabilities.
Key Behavioral Indicators
- Unusual CIP traffic patterns
- Oversized or malformed CIP packet requests
- Unexpected termination of the RSLinx Classic process
False Positive Assessment
Low
Recommendations
Immediate Mitigation
- Verify against your organization's incident response runbook and team escalation paths before acting. Upgrade RSLinx Classic to version 4.60 to remediate the vulnerabilities.
Infrastructure Hardening
- Minimize network exposure for all control system devices and ensure they are not accessible from the internet.
- Isolate control system networks from business networks using firewalls.
- Use VPNs for remote access requirements and ensure they are updated to the most current version available.
User Protection
- N/A
Security Awareness
- Train staff on recognizing and avoiding social engineering attacks that could be used to gain initial access to the network.
- Instruct staff not to click web links or open attachments in unsolicited email messages.
MITRE ATT&CK Mapping
Impact
Related
- Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix (CVE-2021-42260)·3
- Rockwell Automation FLEX I/O EtherNet/IP Adapters (CVE-2026-0646, CVE-2026-0647)·3
- Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP (CVE-2026-11317)·3