CVE-2026-9621
Received Received - Intake

Denial-of-Service in RSLinx Classic via Malformed CIP Packet

Vulnerability report for CVE-2026-9621, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Rockwell Automation

Description

A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
rockwellautomation rslinx_classic *
rockwell_automation rslinx_classic *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial-of-service issue in RSLinx Classic caused by improper handling of a malformed CIP packet. A specially crafted packet can crash the service, requiring a restart to restore normal operation.

Detection Guidance

Detecting this vulnerability requires monitoring for malformed CIP packets targeting RSLinx Classic. Use network traffic analyzers like Wireshark to inspect CIP protocol traffic for unusual patterns or malformed packets. Check RSLinx Classic logs for service crashes or unexpected restarts.

Impact Analysis

The vulnerability allows an attacker to disrupt RSLinx Classic operations by sending a malicious packet, causing service outages that may affect industrial control systems relying on this software.

Compliance Impact

This vulnerability causes denial-of-service by crashing the RSLinx Classic service, which could disrupt industrial control systems. Such disruptions may impact data availability, potentially violating compliance requirements for availability in standards like GDPR and HIPAA that mandate continuous access to critical systems.

Mitigation Strategies

Apply the latest security patches from Rockwell Automation for RSLinx Classic. Restrict network access to RSLinx Classic ports using firewalls. Monitor service stability and implement intrusion detection systems to block malformed CIP packets.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9621. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart