CVE-2026-9622
Received Received - Intake

Denial-of-Service in RSLinx Classic via CIP Packet

Vulnerability report for CVE-2026-9622, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Rockwell Automation

Description

A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
rockwell_automation rslinx_classic *
rockwellautomation rslinx_classic to 4.60 (exc)
rockwellautomation rslinx_classic 4.60

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-191 The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a denial-of-service vulnerability in Rockwell Automation's RSLinx Classic software. A crafted CIP packet targeting the Forward Close service causes an integer underflow, crashing the service and requiring a restart to recover.

Detection Guidance

Monitor RSLinx Classic service logs for crashes or unexpected terminations. Inspect network traffic for malformed CIP packets targeting the Forward Close service using packet capture tools like Wireshark. Check for repeated service restarts as a potential indicator of exploitation.

Impact Analysis

The vulnerability can cause the RSLinx Classic service to crash, disrupting communication between industrial control systems and potentially halting operations that rely on this software.

Mitigation Strategies

Upgrade RSLinx Classic to version V4.60 or later immediately. If upgrading is not possible, restrict network access to the Forward Close service port and monitor for suspicious CIP traffic. Apply network segmentation to isolate affected systems.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9622. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart