Executive brief
RSLinx Classic is communications software used to connect industrial automation devices and systems. A crafted network packet targeting the Forward Close service can crash the RSLinx Classic service, disrupting real-time data access and requiring manual restart to restore operations.
Technical details
An integer underflow vulnerability (CWE-191) exists in RSLinx Classic's handling of the Forward Close service within the Common Industrial Protocol (CIP). An attacker can send a specially crafted CIP packet to trigger an integer underflow condition, causing the RSLinx Classic service to crash. No authentication is required and the vulnerability is network-reachable. An attacker can achieve denial-of-service by causing service unavailability, requiring manual restart to recover. The vulnerability is fixed in version 4.60; affected versions are 4.50 and prior.
Affected products
- Rockwell Automation RSLinx Classic V4.50 and prior
Timeline
- 2026-09-01: disclosed