Rockwell Automation RSLinx Classic

Plan PatchCVSS 8.6ICS-CERT ICSA-26-244-01Sep 1, 2026
Rockwell Automation
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

RSLinx Classic versions 4.50 and earlier contain integer overflow and buffer overflow vulnerabilities (CWE-190, CWE-191, CWE-120) that can be exploited remotely without authentication to cause a denial-of-service condition. Successful exploitation crashes the RSLinx Classic application, disrupting communication with connected PLCs and interrupting industrial process monitoring and control operations.

What this means
What could happen
An attacker on the network could crash RSLinx Classic, disrupting communication with programmable logic controllers (PLCs) and halting real-time monitoring and control of industrial processes until the service is manually restarted.
Who's at risk
This affects manufacturers and utilities using Rockwell Automation RSLinx Classic for PLC programming and monitoring, including water treatment facilities, electrical substations, and industrial plants that rely on Allen-Bradley or MicroLogix controllers for supervisory control.
How it could be exploited
An attacker with network access to the RSLinx Classic service (typically port 2222 or the configured port) sends a specially crafted packet that triggers an integer overflow or buffer overflow condition, causing the application to fail and stop responding to valid client connections.
Prerequisites
  • Network access to RSLinx Classic service port
  • No authentication required
remotely exploitableno authentication requiredlow complexityaffects industrial process control
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (1)
ProductAffected VersionsFix Status
RSLinx Classic≤ 4.50Fix available
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to RSLinx Classic service port to only authorized engineering workstations and authorized hosts on the control network
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate RSLinx Classic to version 4.60 or later
Long-term hardening
0/1
HARDENINGImplement network segmentation to isolate RSLinx Classic and PLC communication from untrusted networks
API: /api/v1/advisories/ae22779c-e17c-43e3-a946-b48c616fb444

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Rockwell Automation RSLinx Classic | CVSS 8.6 - OTPulse