Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-9624
Rockwell Automation RSLinx Classic vulnerability analysis and mitigation

Overview

CVE-2026-9624 is a denial-of-service vulnerability in Rockwell Automation RSLinx® Classic that allows an unauthenticated remote attacker to crash the service by sending a specially crafted CIP (Common Industrial Protocol) packet. The root cause is insufficient data length validation, classified as CWE-191 (Integer Underflow/Wrap or Wraparound). Affected versions include RSLinx Classic V4.50 and prior. The vulnerability was published on September 1, 2026, with a patch available via the vendor advisory. It carries a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Rockwell Advisory).

Technical details

The vulnerability is rooted in an integer underflow (CWE-191) during data length validation when RSLinx Classic processes incoming CIP packets. When a crafted packet with a malformed or undersized data length field is received, the service fails to properly validate the value, leading to a wrap-around condition that causes the service to crash. The attack requires no authentication, no user interaction, and no special privileges — only network access to the RSLinx Classic service port. No public proof-of-concept code has been identified at this time (GitHub Advisory, Rockwell Advisory).

Impact

Successful exploitation causes the RSLinx Classic service to crash, requiring a manual restart to restore functionality. Since RSLinx Classic is widely used as a communication driver for Rockwell Automation PLCs and industrial control systems, a service crash can disrupt OT/ICS operations, interrupt HMI communications, and halt industrial processes dependent on the software. There is no evidence of confidentiality or integrity impact — the vulnerability is limited to availability (GitHub Advisory, CISA ICS Advisory).

Exploitability

There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.312% (24th percentile), indicating a low near-term probability of exploitation. The vulnerability is rated as automatable by NVD SSVC analysis, meaning an attacker could script repeated denial-of-service attacks without manual intervention. No threat actor attribution has been reported, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog (CISA ICS Advisory).

Exploitation steps

  1. Reconnaissance: Identify network-accessible RSLinx Classic instances (V4.50 or prior) using industrial network scanners or tools like Shodan/Censys targeting CIP/EtherNet-IP default port 44818 (TCP/UDP).
  2. Craft malicious CIP packet: Construct a CIP packet with a malformed or undersized data length field designed to trigger an integer underflow during length validation in the RSLinx Classic service.
  3. Transmit packet: Send the crafted packet to the target RSLinx Classic service over the network — no authentication or prior session establishment is required.
  4. Trigger crash: The service fails to handle the malformed length value, resulting in an integer underflow/wraparound that causes the RSLinx Classic process to crash.
  5. Observe impact: The RSLinx Classic service becomes unavailable, disrupting communications between connected HMIs, SCADA systems, and PLCs until an operator manually restarts the service (GitHub Advisory, Rockwell Advisory).

Indicators of compromise

  • Network: Unexpected or malformed CIP/EtherNet-IP packets (port 44818 TCP/UDP) originating from unknown or untrusted IP addresses targeting RSLinx Classic hosts; repeated connection attempts from a single source in a short timeframe.
  • Logs: Windows Event Log entries showing unexpected termination or crash of the RSLinx Classic service (e.g., RSLinx.exe application error events); repeated service stop/start events in the Windows Services log.
  • Process: Unexpected absence or repeated restart of the RSLinx.exe process on the host system; crash dump files (.dmp) generated in the RSLinx Classic installation directory or Windows error reporting folders.
  • File System: Presence of Windows Error Reporting (WER) crash dump files associated with RSLinx.exe in %LocalAppData%\CrashDumps or %SystemRoot%\Minidump (Rockwell Advisory).

Mitigation and workarounds

Rockwell Automation has released a patch addressing this vulnerability; users should upgrade RSLinx Classic beyond V4.50 per the vendor advisory (SD1794). As an interim workaround, implement network-level controls (firewalls, VLANs, or industrial DMZs) to restrict CIP/EtherNet-IP traffic (port 44818) to trusted sources only, following ICS network segmentation best practices. Monitor for repeated RSLinx Classic service crashes as a potential indicator of exploitation attempts (Rockwell Advisory, CISA ICS Advisory).

Community reactions

CISA published an ICS advisory (ICSA-26-244-01) covering this vulnerability, highlighting its relevance to critical infrastructure operators (CISA ICS Advisory). The Hacker News included it in a weekly security recap, and security aggregators such as AusCERT and VulDB catalogued the advisory shortly after disclosure (AusCERT). Community reaction has been measured, consistent with a patched ICS DoS vulnerability without active exploitation.

Additional resources


SourceThis report was generated using AI

Related Rockwell Automation RSLinx Classic vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-9621CRITICAL9.2
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx
NoYesSep 01, 2026
CVE-2026-9625HIGH8.7
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx
NoYesSep 01, 2026
CVE-2026-9624HIGH8.7
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx
NoYesSep 01, 2026
CVE-2026-9622HIGH8.7
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx
NoYesSep 01, 2026
CVE-2020-13573HIGH7.5
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx
NoYesJan 07, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management