Executive Summary

Four critical denial-of-service vulnerabilities (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625) were discovered in Rockwell Automation's RSLinx Classic versions 4.50 and earlier. These vulnerabilities allow attackers to crash the RSLinx Classic service by sending specially crafted CIP packets, exploiting integer overflow, integer underflow, and buffer overflow conditions. The vulnerabilities affect critical manufacturing infrastructure worldwide and require service restarts to recover, potentially disrupting industrial operations and production systems.

These vulnerabilities highlight the growing threat landscape facing industrial control systems as cybercriminals increasingly target critical infrastructure. With the rise of nation-state actors and ransomware groups focusing on OT environments, securing industrial communication protocols like CIP has become paramount for operational resilience.

Why This Matters Now

Industrial control systems are facing unprecedented cyber threats as attackers shift focus to critical infrastructure. These RSLinx Classic vulnerabilities demonstrate how easily OT networks can be disrupted, making immediate patching and network segmentation critical for manufacturing continuity.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

All versions of Rockwell Automation RSLinx Classic 4.50 and earlier are vulnerable to these denial-of-service attacks.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce the attack's blast radius by constraining lateral movement through industrial network segments and limiting attacker reach to critical manufacturing systems beyond the initial RSLinx Classic compromise.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Network segmentation policies would likely limit the attacker's ability to reach RSLinx Classic services across multiple industrial network zones, reducing the scope of vulnerable endpoints accessible for CIP packet exploitation

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Microsegmentation policies would likely constrain the attacker's ability to leverage RSLinx Classic access for broader privilege escalation across industrial device networks, limiting elevated access scope to segmented zones

Lateral Movement

Control: East-West Traffic Security

Mitigation: Traffic inspection and segmentation controls would likely limit the attacker's ability to pivot between industrial network segments, constraining access to PLCs and HMI systems through enforced communication policies

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Network visibility and monitoring capabilities would likely detect and constrain unauthorized industrial protocol communications, limiting the attacker's ability to maintain persistent command channels across network segments

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress filtering and policy controls would likely constrain the attacker's ability to extract industrial data and process configurations, limiting outbound data flows from compromised industrial network segments

Impact (Mitigations)

While RSLinx Classic service disruption may still occur within affected segments, the operational impact would likely be constrained to isolated network zones rather than cascading across the entire manufacturing environment

Impact at a Glance

Affected Business Functions

  • Industrial Process Control
  • Manufacturing Operations
  • SCADA Systems
  • Device Communication Management
Operational Disruption

Estimated downtime: 1 days

Financial Impact

Estimated loss: N/A

Data Exposure

No data exposure identified. Vulnerabilities result in denial-of-service conditions affecting RSLinx Classic service availability but do not compromise data confidentiality or integrity.

Recommended Actions

  • Implement Zero Trust Segmentation to isolate industrial control systems from broader network access and prevent lateral movement between ICS components
  • Deploy Inline IPS (Suricata) to detect and block malformed CIP packets and exploit attempts targeting industrial protocols before they reach critical systems
  • Enable Multicloud Visibility & Control to monitor anomalous interactions and repeated malformed requests against industrial communication services
  • Establish East-West Traffic Security controls to prevent unauthorized lateral movement between industrial network segments and operational technology assets
  • Configure Egress Security & Policy Enforcement to detect unauthorized data exfiltration from industrial systems and block communications to unauthorized external destinations

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image