IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Rockwell Automation RSLinx Classic

HIGH
CVSS 8.6
Date 2026-09-01T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product.

// Vulnerabilities (4)

CVE ID CVSS Score Severity Description
CVE-2026-9622 8.6 high
A denial-of-service security issue exists within RSLinx Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx Classic service to crash, requiring a restart of the service to recover.
CVE-2026-9621 8.6 high
A denial-of-service security issue exists within RSLinx Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx Classic service to crash, requiring a restart of the service to recover.
CVE-2026-9625 7.5 high
A denial-of-service security issue exists within RSLinx Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx Classic service to crash, requiring a restart of the service to recover.
CVE-2026-9624 7.5 high
A denial-of-service security issue exists within RSLinx Classic. A crafted CIP packet can cause the RSLinx Classic service to crash due to insufficient data length validation, requiring a restart of the service to recover.

// Remediations (3)

Mitigation: For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.co
For more information, see Rockwell Automation Security Advisories: https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html.
Mitigation: Users using the affected software, who are not able to upgrade to one of the corrected versions, sho
Users using the affected software, who are not able to upgrade to one of the corrected versions, should use Rockwell Automation's security best practices https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight.
Patch: Rockwell Automation has corrected the vulnerabilities in RSLinx Classic version 4.60.
Rockwell Automation has corrected the vulnerabilities in RSLinx Classic version 4.60.

// References