news.mlab.sh
Back to the feed
threat-intel

Rockwell Automation RSLinx Classic

CriticalCVSS 9.2
Summary

Rockwell Automation has released a security advisory regarding vulnerabilities in RSLinx Classic versions 4.50 and below. These vulnerabilities, stemming from improper packet handling, can lead to denial-of-service conditions and require a restart of the service to recover. Users unable to upgrade should follow Rockwell Automation's security best practices. CISA recommends minimizing network exposure and isolating control systems.

Rockwell Automation has identified and addressed security vulnerabilities within RSLinx Classic, a software used for industrial automation and communication. Specifically, versions 4.50 and earlier are affected. The vulnerabilities arise from the handling of malformed packets, leading to service crashes when a crafted CIP packet is received. This can result in a denial-of-service condition, necessitating a service restart to restore functionality. Rockwell Automation has released a fix in version 4.60. CISA recommends implementing defensive measures to minimize the risk of exploitation, including limiting network exposure and isolating control systems from business networks. Users who cannot upgrade to version 4.60 should adhere to Rockwell Automation's security best practices, which can be found at [https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight](https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight). CISA also advises using more secure remote access methods, such as VPNs, recognizing that VPNs themselves can have vulnerabilities.

Read the full article at CISA Advisories