Junglewise Threat Intelligence

CVE-2026-9621: Rockwell Automation RSLinx Classic denial-of-service via malformed CIP packet

CVE-2026-9621 · Severity: info · CVSS 8.6 · Published 2026-09-01

Technologies: Rockwell Automation RSLinx Classic. Vendors: Rockwell Automation.

Executive brief

RSLinx Classic is communications software from Rockwell Automation used to connect industrial automation devices and systems in manufacturing and control environments. A malformed network packet can crash the RSLinx service, causing loss of connectivity and requiring manual service restart to restore operations.

Technical details

CVE-2026-9621 is a denial-of-service vulnerability caused by improper handling of malformed CIP (Common Industrial Protocol) packets in RSLinx Classic. The root cause is an integer overflow (CWE-190) in packet parsing logic. An unauthenticated remote attacker can send a specially crafted CIP packet to the service to trigger a crash. No workarounds are available; affected versions V4.50 and prior must be upgraded to V4.60 or later to remediate.

Affected products

  • Rockwell Automation RSLinx Classic V4.50 and prior

Timeline

  • 2026-09-01: disclosed

References

Related threats