Executive Summary
CVE-2026-9624 is one of several integer overflow, integer underflow, and buffer copy defects in Rockwell Automation RSLinx Classic through version 4.50 that an attacker can trigger to drive the product into a denial-of-service condition. Because RSLinx Classic is the communication broker sitting between engineering workstations, HMIs, and Allen-Bradley controllers, loss of this service means loss of process visibility and loss of the operator command path to the plant floor.
Technical Exposure Breakdown
The vulnerable component is RSLinx Classic, the driver and message routing layer that maps logical device connections to physical CIP and EtherNet/IP paths. The grounding data identifies affected versions as RSLinx Classic through 4.50 and describes the underlying weakness classes as integer overflow or wraparound, integer underflow, and buffer copy without proper bounds checking. These are memory-handling faults in how the service parses inbound data structures.
The attack vector follows the pattern of these weakness classes: a malformed or oversized message sent to the RSLinx service causes a size or index calculation to wrap past its intended bounds, which then corrupts memory handling or drives an out-of-bounds copy. The result documented here is a denial-of-service outcome, meaning service crash or hang rather than confirmed remote code execution. The precondition is network or local reachability to the RSLinx listener. In practice that means any host on the same segment as the engineering workstation, or any device that can route traffic to it, is a candidate origin point.
No patch status is confirmed in the source material available to us. Treat fix availability as unknown until you validate the vendor advisory against your specific version and platform.
OT Impact and Compliance Risk
RSLinx Classic is not an incidental utility. It is frequently the single path between RSLogix or Studio 5000 programming environments and live controllers. When it drops, the operator loses tag polling, trending, and in many deployments the ability to download or go online with logic. The physical consequence is not that the controller stops. The PLC keeps executing its last program. The consequence is that the humans and the SCADA layer go blind and lose their intervention channel at exactly the moment an attacker or a process upset would want them to.
For NERC CIP registered entities, an RSLinx outage on an interactive remote access or intermediate system path touches CIP-005 and CIP-007 monitoring obligations, and a demonstrated exploit affects your CIP-010 vulnerability assessment posture. Under IEC 62443, this is a zone conduit failure: the flaw undermines the availability property the standard assigns to control-level assets, and it exposes weak segmentation between the engineering zone and the control zone. Pipeline operators under TSA SD-02C should map RSLinx hosts as critical cyber systems and confirm they fall inside the mandated network segmentation and access control boundaries. Water and wastewater utilities operating under AWIA 2018 risk and resilience obligations should account for HMI-to-PLC broker loss in their emergency response planning.
Compensating Controls
Do not treat active vulnerability scanning as a safe discovery method here. Aggressive probing of an RSLinx host or the controllers behind it can itself trigger the exact denial-of-service you are trying to defend against, and CIP parsing stacks on legacy Allen-Bradley hardware have a long history of faulting under unexpected traffic. Enumerate RSLinx installations from asset inventory and workstation software records instead.
- Restrict inbound access to RSLinx hosts to an explicit allowlist of engineering workstations. RSLinx should never be reachable from general enterprise IT ranges.
- Deploy a virtual patch at the segment boundary. A Suricata rule concept: alert and drop on anomalous EtherNet/IP or CIP payloads to the RSLinx listener where declared length fields exceed sane bounds, catching the oversized structures that drive the overflow and wraparound conditions.
- Rate-limit and inspect the conduit between the engineering zone and the control zone so a single malformed session cannot repeatedly crash the service.
- Baseline RSLinx service uptime and alert on unexpected restarts as an early exploitation signal.
- Validate any vendor-supplied fix in a lab or non-production replica before touching a live line, and schedule it inside a planned outage window.
BreachSpider Intel
BreachSpider tracks RSLinx Classic exposure and related Rockwell Automation advisories across the OT vulnerability landscape, and monitoring is available through the BreachSpider platform.