# Critical Buffer Overflow in Rockwell RSLinx Threatens Industrial Control Systems Worldwide
## The Threat
Rockwell Automation has disclosed a critical stack-based buffer overflow vulnerability in RSLinx Classic, a widely deployed industrial software platform used to interface with programmable logic controllers (PLCs) and other control devices across manufacturing, utilities, and infrastructure sectors. The vulnerability, tracked as CVE-2020-13573, can be triggered remotely without authentication, allowing attackers to crash the application or potentially execute arbitrary code on systems that manage critical operations.
RSLinx Classic is a foundational component in countless industrial facilities—it serves as a bridge between human operators and the hardware controlling production lines, power distribution, water treatment, and food processing. The affected versions (4.50.00 and earlier) contain an out-of-bounds read condition that degrades into a full denial-of-service condition where the application becomes unresponsive and will not recover automatically. In environments where RSLinx is handling real-time monitoring or control decisions, even temporary unavailability can cascade into significant operational disruptions.
The vulnerability's network-accessible attack surface is particularly concerning: an attacker positioned anywhere on the network—or potentially from the internet if RSLinx is inadvertently exposed—can trigger the crash without needing valid credentials or user interaction. This means legacy industrial networks that have not segregated control systems from corporate networks, or organizations that have opened remote access ports without proper segmentation, face elevated risk.
## Severity and Impact
| Metric | Details |
|--------|---------|
| CVE ID | CVE-2020-13573 |
| Vulnerability Type | Stack-based Buffer Overflow / Out-of-bounds Read (CWE-125) |
| CVSS v3.1 Base Score | 7.5 (HIGH) |
| CVSS v3.1 Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| CVSS v4.0 Base Score | 8.7 (HIGH) |
| CVSS v4.0 Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
| Attack Vector | Network |
| Authentication Required | None |
| User Interaction | None |
| Primary Impact | Denial of Service; Potential Remote Code Execution |
| Affected Sectors | Critical Manufacturing, Energy, Food and Agriculture, Water and Wastewater |
## Affected Products
- Version 4.50.00 and earlier
- Status: Confirmed vulnerable
## Mitigations
Immediate Actions:
Rockwell Automation strongly recommends that organizations using affected versions upgrade immediately to RSLinx Classic version 4.60.00 or later. This is the primary remediation and should be prioritized in patch management schedules.
For Organizations Unable to Upgrade Immediately:
Network Segmentation and Access Controls:
Given the network-accessible nature of this vulnerability, CISA recommends organizations:
Operational Security:
Security Awareness:
Organizations should educate staff about social engineering attacks that might be used to gain initial network access or to bypass segmentation controls.
## References
---
## HackWire Analysis
This vulnerability illustrates a persistent challenge in industrial cybersecurity: the gap between vendor patch availability and actual deployment in the field. Rockwell's fix has been available for years, yet RSLinx Classic continues to run in thousands of facilities worldwide, many still on vulnerable versions. The reasons are predictable—industrial operations prioritize stability and uptime over patch cycles, and many sites operate under the assumption that air-gapping or network obscurity is sufficient protection.
The reality is more complex. As organizations have increasingly connected legacy systems to corporate networks for remote monitoring and cloud analytics, the perimeter has dissolved. A stack-based buffer overflow on an exposed RSLinx instance is not a theoretical risk—it's a concrete pathway for adversaries to disrupt critical infrastructure. The fact that no public exploitation code exists yet does not mean attackers haven't already developed private exploits. State-sponsored threat actors actively track industrial control system vulnerabilities, and a high-severity remote DoS on a foundational platform like RSLinx is exactly the kind of capability they would weaponize.
Organizations should treat this vulnerability as a forcing function: audit your RSLinx deployments immediately, upgrade to 4.60.00 within the next 30 days if operationally feasible, and if you cannot upgrade, apply patch BF31213 and implement aggressive network segmentation. If RSLinx is running on a system that has any exposure to untrusted networks—including corporate networks—this is non-negotiable. Test patches on a staging environment first, communicate maintenance windows to stakeholders, and plan for the rare possibility that an upgrade reveals compatibility issues that need resolution (though Rockwell's upgrade path from 4.50 to 4.60 is generally smooth).
The larger lesson: evaluate whether you truly need RSLinx exposed to your corporate network at all. Many organizations could achieve their monitoring and reporting goals by implementing a one-way data push (from RSLinx to a central database) rather than two-way connectivity. Segmentation is not convenience—it's the difference between an isolated incident and a widespread outage.
— HackWire Editorial
---
## Related Coverage