Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-9625
Rockwell Automation RSLinx Classic vulnerability analysis and mitigation

Overview

CVE-2026-9625 is a denial-of-service vulnerability in Rockwell Automation's RSLinx® Classic software. A crafted CIP (Common Industrial Protocol) packet containing an oversized embedded message request can cause the RSLinx® Classic service to crash, requiring a manual service restart to recover. The vulnerability affects RSLinx® Classic versions V4.50 and prior. It was published on September 1, 2026, with a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Rockwell Advisory).

Technical details

The root cause is classified as CWE-120 (Buffer Copy without Checking Size of Input / Classic Buffer Overflow), where the RSLinx® Classic service fails to validate the size of an embedded message request within an incoming CIP packet before copying it into a buffer (GitHub Advisory). An unauthenticated remote attacker can exploit this by sending a specially crafted CIP packet with an oversized embedded message over the network, requiring no privileges or user interaction. The attack vector is network-accessible, with low complexity and no special preconditions, making it straightforward to trigger remotely (Rockwell Advisory).

Impact

Successful exploitation results in a crash of the RSLinx® Classic service, causing a complete loss of availability for the affected system until the service is manually restarted. RSLinx® Classic is widely used as a communication driver for Rockwell Automation PLCs and industrial control systems, so a service crash can disrupt OT/ICS environments, potentially halting industrial operations or communications between engineering workstations and field devices. There is no impact on confidentiality or integrity — the vulnerability is limited to availability (GitHub Advisory, CISA ICS Advisory).

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.312% (24th percentile), indicating a low near-term probability of exploitation. The vulnerability is rated as automatable by SSVC assessment, meaning an attacker could script repeated denial-of-service attacks without manual intervention. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE (CISA ICS Advisory).

Exploitation steps

  1. Reconnaissance: Identify network-accessible RSLinx® Classic instances (version V4.50 or prior) using industrial network scanners or tools like Shodan, targeting systems listening on CIP/EtherNet/IP ports (typically TCP/UDP 44818 or TCP 2222).
  2. Craft malicious CIP packet: Construct a CIP packet containing an embedded message request with an oversized payload that exceeds the expected buffer size, exploiting the lack of input size validation (CWE-120).
  3. Transmit the packet: Send the crafted CIP packet to the target RSLinx® Classic service over the network without requiring authentication or user interaction.
  4. Trigger service crash: The oversized embedded message causes a buffer overflow condition in the RSLinx® Classic service, resulting in a service crash and denial of service to all connected clients and applications.
  5. Sustain disruption: Repeatedly send malicious packets to prevent service recovery, as the vulnerability can be re-triggered each time the service is restarted (GitHub Advisory, Rockwell Advisory).

Indicators of compromise

  • Network: Unusual or malformed CIP packets targeting TCP/UDP port 44818 or TCP 2222 with oversized embedded message fields; repeated connection attempts from unexpected external IP addresses to RSLinx® Classic hosts.
  • Logs: RSLinx® Classic service crash events or unexpected service termination entries in Windows Event Logs (Application/System logs); error entries referencing buffer or memory faults in RSLinx® Classic logs.
  • Process: Unexpected termination of the RSLinx® Classic service process (RSLinx.exe); repeated service restart events in Windows Service Control Manager logs.
  • Availability: Loss of communication between engineering workstations and PLCs/field devices coinciding with anomalous network traffic to the RSLinx® Classic host (CISA ICS Advisory).

Mitigation and workarounds

Rockwell Automation has released a security patch addressing this vulnerability; users should upgrade RSLinx® Classic beyond version V4.50 per the vendor advisory (Rockwell Advisory). As interim mitigations, restrict network access to RSLinx® Classic services using firewalls or network segmentation, allowing only trusted hosts to communicate on CIP/EtherNet/IP ports. Additionally, monitor for anomalous CIP traffic patterns and establish rapid service-restart procedures to minimize downtime in the event of exploitation (CISA ICS Advisory).

Community reactions

CISA published an ICS advisory (ICSA-26-244-01) highlighting this vulnerability shortly after disclosure, underscoring its relevance to critical infrastructure operators (CISA ICS Advisory). The vulnerability was also covered in The Hacker News' weekly recap and noted by ICS security-focused outlets such as Meterpreter.org, reflecting moderate community interest given its impact on industrial environments (The Hacker News). No significant researcher controversy or vendor dispute has been observed.

Additional resources


SourceThis report was generated using AI

Related Rockwell Automation RSLinx Classic vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-9621CRITICAL9.2
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx
NoYesSep 01, 2026
CVE-2026-9625HIGH8.7
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx
NoYesSep 01, 2026
CVE-2026-9624HIGH8.7
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx
NoYesSep 01, 2026
CVE-2026-9622HIGH8.7
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx
NoYesSep 01, 2026
CVE-2020-13573HIGH7.5
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx
NoYesJan 07, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management