
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-9624 is a denial-of-service vulnerability in Rockwell Automation RSLinx® Classic that allows an unauthenticated remote attacker to crash the service by sending a specially crafted CIP (Common Industrial Protocol) packet. The root cause is insufficient data length validation, classified as CWE-191 (Integer Underflow/Wrap or Wraparound). Affected versions include RSLinx Classic V4.50 and prior. The vulnerability was published on September 1, 2026, with a patch available via the vendor advisory. It carries a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Rockwell Advisory).
The vulnerability is rooted in an integer underflow (CWE-191) during data length validation when RSLinx Classic processes incoming CIP packets. When a crafted packet with a malformed or undersized data length field is received, the service fails to properly validate the value, leading to a wrap-around condition that causes the service to crash. The attack requires no authentication, no user interaction, and no special privileges — only network access to the RSLinx Classic service port. No public proof-of-concept code has been identified at this time (GitHub Advisory, Rockwell Advisory).
Successful exploitation causes the RSLinx Classic service to crash, requiring a manual restart to restore functionality. Since RSLinx Classic is widely used as a communication driver for Rockwell Automation PLCs and industrial control systems, a service crash can disrupt OT/ICS operations, interrupt HMI communications, and halt industrial processes dependent on the software. There is no evidence of confidentiality or integrity impact — the vulnerability is limited to availability (GitHub Advisory, CISA ICS Advisory).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.312% (24th percentile), indicating a low near-term probability of exploitation. The vulnerability is rated as automatable by NVD SSVC analysis, meaning an attacker could script repeated denial-of-service attacks without manual intervention. No threat actor attribution has been reported, and the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog (CISA ICS Advisory).
RSLinx.exe application error events); repeated service stop/start events in the Windows Services log.RSLinx.exe process on the host system; crash dump files (.dmp) generated in the RSLinx Classic installation directory or Windows error reporting folders.RSLinx.exe in %LocalAppData%\CrashDumps or %SystemRoot%\Minidump (Rockwell Advisory).Rockwell Automation has released a patch addressing this vulnerability; users should upgrade RSLinx Classic beyond V4.50 per the vendor advisory (SD1794). As an interim workaround, implement network-level controls (firewalls, VLANs, or industrial DMZs) to restrict CIP/EtherNet-IP traffic (port 44818) to trusted sources only, following ICS network segmentation best practices. Monitor for repeated RSLinx Classic service crashes as a potential indicator of exploitation attempts (Rockwell Advisory, CISA ICS Advisory).
CISA published an ICS advisory (ICSA-26-244-01) covering this vulnerability, highlighting its relevance to critical infrastructure operators (CISA ICS Advisory). The Hacker News included it in a weekly security recap, and security aggregators such as AusCERT and VulDB catalogued the advisory shortly after disclosure (AusCERT). Community reaction has been measured, consistent with a patched ICS DoS vulnerability without active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."