External risk intelligence

RSLinx Classic Malformed Packet Denial-of-Service Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-9621

RSLinx Classic is an industrial communication server used primarily in local operational technology (OT) environments to facilitate communication between industrial devices and software. While it utilizes network protocols, it is typically deployed within isolated internal industrial control networks, making public internet exposure uncommon and contrary to standard security practices.

Integer Overflow

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability has been identified in RSLinx® Classic, a technology used for industrial communication. This issue stems from how the software handles improperly formatted data packets, which can cause the RSLinx® Classic service to stop working unexpectedly and require a manual restart. The main concern is to confirm if this technology is in use within your environment and understand any potential exposure.

  • Software can crash from bad data.
  • It affects industrial communication systems.
  • Assess for RSLinx Classic usage and impact.

Attack Path

How an attacker could exploit the issue

An attacker could remotely send a specially crafted network packet to a vulnerable system. This malformed packet targets the RSLinx Classic service, causing it to crash and become unavailable. The vulnerability allows for a denial-of-service condition, disrupting operations until the service is manually restarted.

  • Network access is required.
  • A malformed packet triggers the issue.
  • Service crash causes denial-of-service.

Live Threat

Current exploitation, exposure, and threat context

A denial-of-service vulnerability in RSLinx Classic could allow an attacker to crash the service by sending a malformed CIP packet. This would disrupt normal operations, requiring manual intervention to restart the affected service.

  • Service availability at risk.
  • Malformed network packet causes crash.
  • Service disruption and operational downtime.

Operational Fix

Recommended remediation, mitigation, and detection steps

The RSLinx Classic service is susceptible to a denial-of-service vulnerability when processing malformed CIP packets, leading to a crash that requires a service restart. Given this is an industrial communication server, likely deployed in isolated operational technology (OT) environments, the primary focus should be on internal network exposure and criticality assessment. Infrastructure or platform teams managing the OT environment, along with security teams overseeing network segmentation and access controls, are likely responsible for addressing this. The first practical step involves identifying all instances of RSLinx Classic, determining their reachability within the OT network, confirming their business criticality, and then engaging the accountable owner to plan a remediation strategy based on the assessed risk.

  • Ownership lies with OT infrastructure/platform teams.
  • Verify internal reachability and business criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is RSLinx Classic?

RSLinx Classic is an industrial communication server developed by Rockwell Automation. It acts as a bridge, allowing software applications to communicate with industrial controllers and devices on the factory floor, typically within operational technology environments.

How does CVE-2026-9621 cause a service crash?

This vulnerability is related to an integer overflow issue, classified as CWE-190. When the software receives a malformed CIP (Common Industrial Protocol) packet, it fails to handle the data correctly, which causes the service to stop unexpectedly.

Does any network traffic trigger this vulnerability?

No. The vulnerability is triggered specifically by a crafted, malformed CIP packet. Normal, well-formed communication traffic used for standard industrial operations does not cause the service to crash.

Should I be worried if my RSLinx system is internal?

According to Halo Surface Signal, RSLinx Classic is usually deployed within isolated internal OT networks. While the CVSS vector notes network reachability, internet exposure is rare and contrary to standard practices, making external exploitation unlikely.

What should I do if I use RSLinx Classic?

First, locate all instances of RSLinx Classic in your environment. Evaluate the criticality of those systems to your operations, check their network accessibility, and work with your infrastructure teams to plan a risk-based remediation strategy.

References