Executive brief
RSLinx Classic is communications software from Rockwell Automation used to connect industrial automation devices and systems in manufacturing and control environments. A malformed network packet can crash the RSLinx service, causing loss of connectivity and requiring manual service restart to restore operations.
Technical details
CVE-2026-9621 is a denial-of-service vulnerability caused by improper handling of malformed CIP (Common Industrial Protocol) packets in RSLinx Classic. The root cause is an integer overflow (CWE-190) in packet parsing logic. An unauthenticated remote attacker can send a specially crafted CIP packet to the service to trigger a crash. No workarounds are available; affected versions V4.50 and prior must be upgraded to V4.60 or later to remediate.
Affected products
- Rockwell Automation RSLinx Classic V4.50 and prior
Timeline
- 2026-09-01: disclosed