Rockwell Automation RSLinx Classic versions 4.50 and earlier contain four network-exploitable denial-of-service vulnerabilities (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625). These flaws stem from integer overflows, underflows, and buffer overflows in the handling of crafted CIP packets, allowing an unauthenticated remote attacker to crash the service. A fix is available in version 4.60.
RSLinx Classic
1 post
Rockwell Automation RSLinx Classic (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624 +1 more)