CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Rockwell Automation RSLinx Classic

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5488

As cited

Copy frozen at (site build).

vulnerabilities

Rockwell Automation RSLinx Classic

Rockwell Automation disclosed four denial-of-service vulnerabilities in RSLinx Classic version 4.50 and earlier, affecting industrial control systems worldwide. The flaws stem from improper handling of crafted CIP packets that can crash the RSLinx Classic service and include integer overflow, integer underflow, and buffer overflow issues. Rockwell Automation has released version 4.60 to address these vulnerabilities, with CVSS v3.1 scores ranging from 7.5 to 8.6 (high severity).

Why it matters: Organizations running RSLinx Classic in critical manufacturing environments face service disruptions from remote, unauthenticated attacks and should upgrade to version 4.60 immediately or apply network isolation controls and Rockwell security best practices.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Rockwell Automation RSLinx Classic

Rockwell Automation disclosed four denial-of-service vulnerabilities in RSLinx Classic version 4.50 and earlier, affecting industrial control systems worldwide. The flaws stem from improper handling of crafted CIP packets that can crash the RSLinx Classic service and include integer overflow, integer underflow, and buffer overflow issues. Rockwell Automation has released version 4.60 to address these vulnerabilities, with CVSS v3.1 scores ranging from 7.5 to 8.6 (high severity).

Why it matters: Organizations running RSLinx Classic in critical manufacturing environments face service disruptions from remote, unauthenticated attacks and should upgrade to version 4.60 immediately or apply network isolation controls and Rockwell security best practices.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary