
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-9625 is a denial-of-service vulnerability in Rockwell Automation's RSLinx® Classic software. A crafted CIP (Common Industrial Protocol) packet containing an oversized embedded message request can cause the RSLinx® Classic service to crash, requiring a manual service restart to recover. The vulnerability affects RSLinx® Classic versions V4.50 and prior. It was published on September 1, 2026, with a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Rockwell Advisory).
The root cause is classified as CWE-120 (Buffer Copy without Checking Size of Input / Classic Buffer Overflow), where the RSLinx® Classic service fails to validate the size of an embedded message request within an incoming CIP packet before copying it into a buffer (GitHub Advisory). An unauthenticated remote attacker can exploit this by sending a specially crafted CIP packet with an oversized embedded message over the network, requiring no privileges or user interaction. The attack vector is network-accessible, with low complexity and no special preconditions, making it straightforward to trigger remotely (Rockwell Advisory).
Successful exploitation results in a crash of the RSLinx® Classic service, causing a complete loss of availability for the affected system until the service is manually restarted. RSLinx® Classic is widely used as a communication driver for Rockwell Automation PLCs and industrial control systems, so a service crash can disrupt OT/ICS environments, potentially halting industrial operations or communications between engineering workstations and field devices. There is no impact on confidentiality or integrity — the vulnerability is limited to availability (GitHub Advisory, CISA ICS Advisory).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The EPSS score is approximately 0.312% (24th percentile), indicating a low near-term probability of exploitation. The vulnerability is rated as automatable by SSVC assessment, meaning an attacker could script repeated denial-of-service attacks without manual intervention. No threat actor attribution or CISA KEV catalog listing has been identified for this CVE (CISA ICS Advisory).
RSLinx.exe); repeated service restart events in Windows Service Control Manager logs.Rockwell Automation has released a security patch addressing this vulnerability; users should upgrade RSLinx® Classic beyond version V4.50 per the vendor advisory (Rockwell Advisory). As interim mitigations, restrict network access to RSLinx® Classic services using firewalls or network segmentation, allowing only trusted hosts to communicate on CIP/EtherNet/IP ports. Additionally, monitor for anomalous CIP traffic patterns and establish rapid service-restart procedures to minimize downtime in the event of exploitation (CISA ICS Advisory).
CISA published an ICS advisory (ICSA-26-244-01) highlighting this vulnerability shortly after disclosure, underscoring its relevance to critical infrastructure operators (CISA ICS Advisory). The vulnerability was also covered in The Hacker News' weekly recap and noted by ICS security-focused outlets such as Meterpreter.org, reflecting moderate community interest given its impact on industrial environments (The Hacker News). No significant researcher controversy or vendor dispute has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."