Junglewise Threat Intelligence

CVE-2026-9622: Rockwell Automation RSLinx Classic denial-of-service in Forward Close service

CVE-2026-9622 · Severity: info · CVSS 9.2 · Published 2026-09-01

Technologies: Rockwell Automation RSLinx Classic. Vendors: Rockwell Automation.

Executive brief

RSLinx Classic is communications software used to connect industrial automation devices and systems. A crafted network packet targeting the Forward Close service can crash the RSLinx Classic service, disrupting real-time data access and requiring manual restart to restore operations.

Technical details

An integer underflow vulnerability (CWE-191) exists in RSLinx Classic's handling of the Forward Close service within the Common Industrial Protocol (CIP). An attacker can send a specially crafted CIP packet to trigger an integer underflow condition, causing the RSLinx Classic service to crash. No authentication is required and the vulnerability is network-reachable. An attacker can achieve denial-of-service by causing service unavailability, requiring manual restart to recover. The vulnerability is fixed in version 4.60; affected versions are 4.50 and prior.

Affected products

  • Rockwell Automation RSLinx Classic V4.50 and prior

Timeline

  • 2026-09-01: disclosed

References

Related threats