CISA Flags Multiple Denial-of-Service Vulnerabilities in Rockwell Automation RSLinx Classic
CISA has issued an alert for multiple denial-of-service vulnerabilities in Rockwell Automation's RSLinx Classic software, versions 4.50 and earlier.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published a critical advisory detailing several denial-of-service (DoS) vulnerabilities affecting Rockwell Automation's RSLinx Classic software. These vulnerabilities, identified under CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, and CVE-2026-9625, impact versions 4.50 and earlier of the widely used industrial automation software.
Exploitation of these flaws allows an unauthenticated attacker to remotely crash the RSLinx Classic service. The attacks are initiated by sending specially crafted CIP (Common Industrial Protocol) packets to the affected system. Successful exploitation would render the service unavailable, requiring a manual restart to restore functionality. The vulnerabilities stem from improper handling of malformed packets, including integer overflows/underflows and buffer copy operations without adequate size validation.
Rockwell Automation's RSLinx Classic software plays a crucial role in industrial control systems (ICS), facilitating communication between various devices and software applications. The affected versions are deployed globally across critical infrastructure sectors, particularly in manufacturing. The potential for a denial-of-service condition could disrupt operations, leading to significant downtime and financial losses.
The Common Vulnerabilities and Exposures (CVE) list details specific weaknesses. CVE-2026-9621 involves improper handling of malformed packets, leading to a service crash. CVE-2026-9622 targets the Forward Close service with a crafted CIP packet, also resulting in a crash. CVE-2026-9624 exploits insufficient data length validation in CIP packets, causing the service to fail. Finally, CVE-2026-9625 involves an oversized embedded message request within a CIP packet that overwhelms the service.
These vulnerabilities carry significant risk, with CVSS v3.1 scores ranging from 7.5 to 8.6 (High), and CVSS v4.0 scores reaching up to 9.2 (Critical). The high scores are attributed to the lack of authentication requirements, network accessibility, and the severe impact on availability. The ability for an unauthenticated attacker to cause a denial-of-service condition without any user interaction makes these flaws particularly dangerous for industrial environments.
Rockwell Automation has addressed these vulnerabilities by releasing version 4.60 of RSLinx Classic. Users are strongly advised to upgrade to this patched version to mitigate the risks. For organizations unable to upgrade immediately, Rockwell Automation recommends implementing their security best practices, which can be found on their support website. Further details and advisories are available on Rockwell Automation's Trust Center.
The disclosure highlights the ongoing challenges in securing operational technology (OT) environments. Industrial control systems often have long lifecycles, and patching can be complex due to the critical nature of the operations they manage. CISA's alert serves as a reminder for organizations to proactively manage their ICS assets, apply vendor patches promptly, and implement robust security measures to protect against potential disruptions.