CVE-2026-9624
Received Received - Intake

Denial-of-Service in RSLinx Classic via CIP Packet

Vulnerability report for CVE-2026-9624, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Rockwell Automation

Description

A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length validation, requiring a  restart of the service to recover.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
rockwell_automation rslinx_classic *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-191 The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial-of-service issue in RSLinx Classic. A specially crafted CIP packet can crash the service due to improper data length validation. The service must be restarted to recover from the crash.

Detection Guidance

Detecting this vulnerability requires monitoring for unexpected crashes in RSLinx Classic or unusual network traffic patterns targeting CIP packets. Check RSLinx Classic logs for service termination events and inspect network traffic for malformed CIP packets using tools like Wireshark with CIP protocol filters.

Impact Analysis

The vulnerability allows an attacker to disrupt RSLinx Classic operations by sending a malformed packet. This can cause service outages, leading to loss of communication with industrial control systems and potential downtime in automated processes.

Mitigation Strategies

Apply vendor patches or updates for RSLinx Classic if available. Isolate affected systems from untrusted networks, restrict network access to CIP ports, and monitor service stability. Consider disabling RSLinx Classic if not essential until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-9624. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart