Executive brief
RSLinx Classic is industrial automation software from Rockwell Automation that connects Allen-Bradley devices and applications, running as a Windows service to manage real-time data access and control. An attacker can send a specially crafted network packet (CIP protocol) with an oversized embedded message to crash the service, forcing a restart and causing an operational outage in industrial automation environments.
Technical details
CVE-2026-9625 is a buffer overflow vulnerability (CWE-120) in RSLinx Classic's CIP packet handling. The vulnerability occurs when processing a crafted CIP packet containing an oversized embedded message request, causing insufficient bounds checking on the input data. The attack is network-based and requires no authentication or user interaction—an attacker only needs network connectivity to the service to send the malicious packet. Successful exploitation results in a crash of the RSLinx Classic service, requiring manual restart. The vulnerability affects versions 4.50 and prior; patches are available in version 4.60 and later.
Affected products
- Rockwell Automation RSLinx Classic 4.50 and prior
Timeline
- 2026-09-01: disclosed
- 2026-09-01: patched: Patch available in RSLinx Classic v4.60