Rockwell Automation RSLinx Classic < 4.60 Multiple Vulnerabilities (SD1794)

critical Nessus Plugin ID 342353

Synopsis

An application installed on the remote Windows host is affected by multiple denial of service vulnerabilities.

Description

The version of Rockwell Automation RSLinx Classic installed on the remote Windows host is 4.50 or prior. It is, therefore, affected by multiple denial of service vulnerabilities:

- A denial-of-service security issue exists within RSLinx Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx Classic service to crash, requiring a restart of the service to recover. (CVE-2026-9621)

- A denial-of-service security issue exists within RSLinx Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx Classic service to crash, requiring a restart of the service to recover.
(CVE-2026-9622)

- A denial-of-service security issue exists within RSLinx Classic. A crafted CIP packet can cause the RSLinx Classic service to crash due to insufficient data length validation, requiring a restart of the service to recover.
(CVE-2026-9624)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Rockwell Automation RSLinx Classic version 4.60 or later.

See Also

https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-01

http://www.nessus.org/u?26912f52

Plugin Details

Severity: Critical

ID: 342353

File Name: rockwell_rslinx_classic_sd_1794.nasl

Version: 1.1

Type: Local

Agent: windows

Family: SCADA

Published: 9/2/2026

Updated: 9/2/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.62

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

CVSS Score Source: CVE-2026-9621

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS v4

Risk Factor: Critical

Base Score: 9.2

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H

Vulnerability Information

CPE: cpe:/a:rockwellautomation:rslinx_classic

Required KB Items: SMB/Registry/Enumerated, installed_sw/Rockwell Automation RSLinx Classic

Patch Publication Date: 9/1/2026

Vulnerability Publication Date: 9/1/2026

Reference Information

CVE: CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625

ICSA: 26-244-01