Rockwell Automation RSLinx Classic

Summary

Rockwell Automation RSLinx Classic versions 4.50 and earlier are affected by multiple vulnerabilities, including integer overflows, underflows, and buffer overflows. Successful exploitation could lead to a denial-of-service condition, causing the affected product to crash and require a restart.

IFF Assessment

FOE

These vulnerabilities allow for denial-of-service conditions, which negatively impact the availability and integrity of industrial control systems.

Severity

8.6 High

The CVSS score of 8.6 is assigned due to the severity of denial-of-service conditions in critical infrastructure, stemming from vulnerabilities like buffer overflows and improper packet handling, which are exploitable remotely.

Defender Context

This alert highlights critical vulnerabilities in Rockwell Automation's RSLinx Classic, a widely used industrial control system component. Defenders in critical manufacturing sectors must prioritize patching or mitigating these issues to prevent denial-of-service attacks that could disrupt operations. Closely monitoring for any exploitation attempts and reviewing network segmentation are crucial defensive measures.

Read Full Story →