Rockwell Automation RSLinx Classic EtherNet/IP Denial-of-Service Vulnerability
Security Advisory Brief
A denial-of-service vulnerability has been identified in the EtherNet/IP server functionality of Rockwell Automation RSLinx Classic, a communication server used throughout industrial environments to broker connectivity between engineering, human-machine interface (HMI), and supervisory control and data acquisition (SCADA) applications and Allen-Bradley controllers. An unauthenticated attacker with network access to the affected service can crash the application, disrupting communication with the programmable logic controllers (PLCs) and field devices that depend on it. On June 16, 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) reissued the associated advisory, drawing renewed attention to the risk this flaw poses to operational technology (OT) environments that continue to run unpatched versions.
The vulnerability, tracked as CVE-2020-13573, stems from an out-of-bounds read in how RSLinx Classic processes Common Industrial Protocol (CIP) requests. By sending a specially crafted sequence of packets — a Register Session request followed by a Send Unit Data message in which the declared Address Item Length is smaller than the data that follows — an attacker can drive the server to read beyond the bounds of an allocated buffer. The result is that the RSLinx Classic application becomes unresponsive and does not recover on its own, requiring a manual service restart or a reboot of the host to restore communications.
Because RSLinx Classic frequently sits at the boundary between enterprise and control networks, a successful attack can interrupt visibility and control across an entire cell or line. The attack requires no authentication, no user interaction, and only low complexity to carry out, and the affected EtherNet/IP service listens on a well-known TCP port that is routinely discoverable through internet scanning. Although the vulnerability has not been observed under active exploitation, its low barrier to abuse and its position in time-sensitive industrial processes make it a meaningful availability risk that warrants prompt remediation.
Threats and Vulnerabilities
CVE-2020-13573, with a CVSS v3.1 base score of 7.5 and a CISA-assigned CVSS v4.0 score of 8.7, is an out-of-bounds read vulnerability in the EtherNet/IP server component of Rockwell Automation RSLinx Classic. The flaw affects RSLinx Classic versions 4.50.00 and earlier and was corrected in version 4.60.00. The CVSS v3.1 vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) reflects a network-exploitable condition that requires low attack complexity, no privileges, and no user interaction, with impact confined to availability. When an attacker submits a malformed CIP sequence in which the Address Item Length field understates the length of the data that follows, RSLinx Classic reads past the end of an allocated buffer and enters an unresponsive state. Some sources characterize the underlying weakness as a use of an out-of-range pointer offset, and vendor documentation notes the possibility of a stack-based condition, but the confirmed and consistently reproduced impact is denial of service rather than code execution. Because the service does not restart automatically, the outage persists until an operator intervenes.
Client Impact
RSLinx Classic runs on Windows hosts and serves as the communication backbone linking engineering workstations, HMI and SCADA software, and Allen-Bradley controllers over EtherNet/IP. When the service crashes, communication with PLCs, remote I/O modules, and other automation equipment is severed, and any application that relies on RSLinx for tag access or device connectivity loses visibility and control. In continuous or time-sensitive processes, even a short interruption can force a line stoppage, trigger safe-state transitions, or require operators to fall back to manual control while the service is restarted. Recovery typically demands hands-on intervention — restarting the RSLinx service or rebooting the affected machine — which extends downtime beyond the initial disruption.
The operational exposure is amplified by how these systems are commonly deployed. RSLinx hosts are frequently long-lived, are difficult to patch during production, and in some environments remain reachable from broader network segments. Internet-facing instances are discoverable through scanning of the EtherNet/IP service port, and organizations subject to critical-infrastructure regulation may face compliance obligations under frameworks such as NERC CIP or the requirements tied to IEC 62443 to demonstrate that known vulnerabilities in control-system software are identified and remediated. An unaddressed, remotely triggerable denial-of-service condition in a core communication component can therefore carry both direct operational and regulatory consequences.
Mitigations
The following actions are recommended to reduce exposure to CVE-2020-13573:
- Upgrade RSLinx Classic to version 4.60.00 or later, which corrects the flawed handling of malformed CIP sequences and is the primary remediation.
- Where an immediate upgrade is not feasible, apply the vendor-supplied patch (identified by Rockwell Automation as BF31213) for the currently installed version.
- Restrict network access to the EtherNet/IP service by placing RSLinx hosts behind properly configured firewalls and within segmented control-network zones, and remove any direct exposure of the service to the internet.
- Enforce least-privilege network paths so that only authorized engineering and application hosts can reach the RSLinx EtherNet/IP service, using access control lists or an industrial demilitarized zone (IDMZ) to broker cross-zone traffic.
- Monitor for anomalous or malformed CIP traffic and for unexpected RSLinx service crashes or restarts, and establish a documented procedure to restore the service quickly if it becomes unresponsive.
Applying these measures together — patching where possible and constraining network reachability where it is not — substantially lowers the likelihood that this vulnerability can be triggered against production systems.
1898 & Co. Response
1898 & Co. works alongside asset owners and operators to reduce risk across industrial and operational technology environments, drawing on hands-on experience with control-system software such as RSLinx Classic and the EtherNet/IP protocols that connect it to field devices. Our teams help organizations inventory affected software, assess exposure, and plan remediation in a way that accounts for the operational constraints of live production systems.
For environments where immediate patching is not practical, 1898 & Co. supports the design and validation of compensating controls, including network segmentation, IDMZ architecture, and monitoring strategies tuned to industrial protocols. This work is intended to reduce the attack surface around vulnerable communication servers while a durable upgrade path is sequenced into maintenance windows.
Beyond point remediation, 1898 & Co. provides threat hunting, incident response, and managed detection services built specifically for OT environments. These offerings help clients detect the malformed protocol activity and service disruptions associated with vulnerabilities like CVE-2020-13573 and respond effectively when anomalous behavior is observed.