Rockwell Automation RSLinx Classic
Plan PatchCVSS 8.6ICS-CERT ICSA-26-244-01Sep 1, 2026
Rockwell Automation
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
RSLinx Classic versions 4.50 and earlier contain integer overflow and buffer overflow vulnerabilities (CWE-190, CWE-191, CWE-120) that can be exploited remotely without authentication to cause a denial-of-service condition. Successful exploitation crashes the RSLinx Classic application, disrupting communication with connected PLCs and interrupting industrial process monitoring and control operations.
What this means
What could happen
An attacker on the network could crash RSLinx Classic, disrupting communication with programmable logic controllers (PLCs) and halting real-time monitoring and control of industrial processes until the service is manually restarted.
Who's at risk
This affects manufacturers and utilities using Rockwell Automation RSLinx Classic for PLC programming and monitoring, including water treatment facilities, electrical substations, and industrial plants that rely on Allen-Bradley or MicroLogix controllers for supervisory control.
How it could be exploited
An attacker with network access to the RSLinx Classic service (typically port 2222 or the configured port) sends a specially crafted packet that triggers an integer overflow or buffer overflow condition, causing the application to fail and stop responding to valid client connections.
Prerequisites
- Network access to RSLinx Classic service port
- No authentication required
remotely exploitableno authentication requiredlow complexityaffects industrial process control
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (1)
ProductAffected VersionsFix Status
RSLinx Classic≤ 4.50Fix available
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict network access to RSLinx Classic service port to only authorized engineering workstations and authorized hosts on the control network
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate RSLinx Classic to version 4.60 or later
Long-term hardening
0/1HARDENINGImplement network segmentation to isolate RSLinx Classic and PLC communication from untrusted networks
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/ae22779c-e17c-43e3-a946-b48c616fb444Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.