Horizon Alert
Summary of the vulnerability and why it matters
A security vulnerability has been identified in RSLinx® Classic, a technology used for industrial communication. This issue stems from how the software handles improperly formatted data packets, which can cause the RSLinx® Classic service to stop working unexpectedly and require a manual restart. The main concern is to confirm if this technology is in use within your environment and understand any potential exposure.
- Software can crash from bad data.
- It affects industrial communication systems.
- Assess for RSLinx Classic usage and impact.
Attack Path
How an attacker could exploit the issue
An attacker could remotely send a specially crafted network packet to a vulnerable system. This malformed packet targets the RSLinx Classic service, causing it to crash and become unavailable. The vulnerability allows for a denial-of-service condition, disrupting operations until the service is manually restarted.
- Network access is required.
- A malformed packet triggers the issue.
- Service crash causes denial-of-service.
Live Threat
Current exploitation, exposure, and threat context
A denial-of-service vulnerability in RSLinx Classic could allow an attacker to crash the service by sending a malformed CIP packet. This would disrupt normal operations, requiring manual intervention to restart the affected service.
- Service availability at risk.
- Malformed network packet causes crash.
- Service disruption and operational downtime.
Operational Fix
Recommended remediation, mitigation, and detection steps
The RSLinx Classic service is susceptible to a denial-of-service vulnerability when processing malformed CIP packets, leading to a crash that requires a service restart. Given this is an industrial communication server, likely deployed in isolated operational technology (OT) environments, the primary focus should be on internal network exposure and criticality assessment. Infrastructure or platform teams managing the OT environment, along with security teams overseeing network segmentation and access controls, are likely responsible for addressing this. The first practical step involves identifying all instances of RSLinx Classic, determining their reachability within the OT network, confirming their business criticality, and then engaging the accountable owner to plan a remediation strategy based on the assessed risk.
- Ownership lies with OT infrastructure/platform teams.
- Verify internal reachability and business criticality.
- Plan remediation based on assessed risk.