Executive brief
RSLinx Classic is industrial communications software used by manufacturing and automation facilities to connect Allen-Bradley devices to control systems. A specially crafted network packet can crash the RSLinx service, forcing manual restart and causing temporary loss of real-time monitoring and device connectivity in critical automation environments.
Technical details
This vulnerability is a denial-of-service condition triggered by insufficient validation of data length in CIP (Common Industrial Protocol) packets processed by RSLinx Classic. The root cause is an integer underflow in packet parsing that occurs when a malformed CIP packet with inadequate length fields is received. An attacker with network access to the RSLinx service can send a crafted CIP packet to trigger a service crash; no authentication is required. The impact is service unavailability requiring manual restart. Patches are available in version 4.60 and later.
Affected products
- Rockwell Automation RSLinx Classic V4.50 and prior
Timeline
- 2026-09-01: disclosed