As cited
Copy frozen at (site build).
vulnerabilities
Rockwell Automation RSLinx Classic
Rockwell Automation disclosed four denial-of-service vulnerabilities in RSLinx Classic version 4.50 and earlier, affecting industrial control systems worldwide. The flaws stem from improper handling of crafted CIP packets that can crash the RSLinx Classic service and include integer overflow, integer underflow, and buffer overflow issues. Rockwell Automation has released version 4.60 to address these vulnerabilities, with CVSS v3.1 scores ranging from 7.5 to 8.6 (high severity).
Why it matters: Organizations running RSLinx Classic in critical manufacturing environments face service disruptions from remote, unauthenticated attacks and should upgrade to version 4.60 immediately or apply network isolation controls and Rockwell security best practices.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Rockwell Automation RSLinx Classic
Rockwell Automation disclosed four denial-of-service vulnerabilities in RSLinx Classic version 4.50 and earlier, affecting industrial control systems worldwide. The flaws stem from improper handling of crafted CIP packets that can crash the RSLinx Classic service and include integer overflow, integer underflow, and buffer overflow issues. Rockwell Automation has released version 4.60 to address these vulnerabilities, with CVSS v3.1 scores ranging from 7.5 to 8.6 (high severity).
Why it matters: Organizations running RSLinx Classic in critical manufacturing environments face service disruptions from remote, unauthenticated attacks and should upgrade to version 4.60 immediately or apply network isolation controls and Rockwell security best practices.
- Source published
- First seen by Cybersecurity Tracker