Junglewise Threat Intelligence

CVE-2026-9625: Rockwell Automation RSLinx Classic denial-of-service in CIP packet handling

CVE-2026-9625 · Severity: info · CVSS 8.7 · Published 2026-09-01

Technologies: Rockwell Automation RSLinx Classic. Vendors: Rockwell Automation.

Executive brief

RSLinx Classic is industrial automation software from Rockwell Automation that connects Allen-Bradley devices and applications, running as a Windows service to manage real-time data access and control. An attacker can send a specially crafted network packet (CIP protocol) with an oversized embedded message to crash the service, forcing a restart and causing an operational outage in industrial automation environments.

Technical details

CVE-2026-9625 is a buffer overflow vulnerability (CWE-120) in RSLinx Classic's CIP packet handling. The vulnerability occurs when processing a crafted CIP packet containing an oversized embedded message request, causing insufficient bounds checking on the input data. The attack is network-based and requires no authentication or user interaction—an attacker only needs network connectivity to the service to send the malicious packet. Successful exploitation results in a crash of the RSLinx Classic service, requiring manual restart. The vulnerability affects versions 4.50 and prior; patches are available in version 4.60 and later.

Affected products

  • Rockwell Automation RSLinx Classic 4.50 and prior

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: patched: Patch available in RSLinx Classic v4.60

References

Related threats