ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Hikvision and Rockwell Automation CVSS 9.8 Flaws Added to CISA KEV Catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2017-7921CVE-2021-22681

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-7921
Improper Authentication Bypass in Multiple Hikvision Products

CVE-2017-7921 is an improper authentication flaw (CWE-287) in multiple Hikvision products that allows an attacker to defeat the devices' authentication checks. It is triggered by sending specially crafted requests to an affected device, causing it to treat the attacker as an authenticated user. A successful attacker gains privilege escalation on the device and access to sensitive information. Any organization running affected Hikvision products, particularly devices reachable from the internet, is affected; the source data does not specify the individual models or firmware version ranges. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2026-03-05, confirming exploitation in the wild (ransomware use unknown), and EPSS assigns a ~100% probability of exploitation within 30 days.

Do: Upgrade affected Hikvision devices to vendor-fixed firmware per Hikvision's security advisories (the data here does not name specific fixed versions), and follow CISA's required actions or BOD 22-01 guidance if applicable. Reduce exposure by removing affected devices from direct internet access and restricting the management interface to trusted networks. Check device logs and configurations for signs of unauthenticated or unauthorized access.

9.8100% KEV
  • Hikvision
mass~1,000,000+ deployed devices, with hundreds of thousands internet-exposed
CVE-2021-22681
Authentication Bypass in Rockwell Automation Studio 5000 Logix Designer and Logix PLCs

Rockwell Automation's Studio 5000 Logix Designer (versions 21 and later) and RSLogix 5000 (versions 16 through 20) use a shared key to verify that they are communicating with genuine Allen-Bradley Logix controllers, and an unauthenticated remote attacker can bypass this verification mechanism (CWE-522, insufficient protection of credentials). The attack requires only network access to the affected software or controllers - no credentials, no user interaction, and no special conditions (CVSS 3.1: 9.8). By bypassing the verification, an attacker can authenticate to CompactLogix, ControlLogix, DriveLogix, Compact GuardLogix, GuardLogix and SoftLogix controllers and interact with the PLCs, potentially tampering with industrial processes. Any deployment running the affected engineering software versions with the listed Logix controller families is in scope, which spans a very large share of Rockwell's installed base. CISA added this flaw to its Known Exploited Vulnerabilities catalog on 2026-03-05 (ransomware use unknown), and EPSS puts the 30-day exploitation probability at roughly 64%; no public proof-of-concept is known.

Do: Apply mitigations per Rockwell's instructions - the vendor has advised disconnecting internet-facing connections, so remove internet exposure from affected controllers and engineering workstations and segment OT networks. Follow applicable CISA BOD 22-01 guidance, and inventory for Studio 5000 Logix Designer v21+ or RSLogix 5000 v16-20 used with the listed controllers; upgrade per vendor guidance or discontinue use if mitigations are unavailable.

9.864% KEV
  • Rockwell Automation Studio 5000 Logix Designer v21 and later
  • Rockwell Automation RSLogix 5000 v16 through v20
  • Rockwell Automation FactoryTalk Services Platform
  • +6 more
massroughly 1 million or more Logix controller installations (tens of thousands likely internet-exposed)
Full article292 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananMar 06, 2026Vulnerability / Network Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Hikvision and Rockwell Automation products to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The critical-severity vulnerabilities are listed below -

  • CVE-2017-7921 (CVSS score: 9.8) - An improper authentication vulnerability affecting multiple Hikvision products that could allow a malicious user to escalate privileges on the system and gain access to sensitive information.
  • CVE-2021-22681 (CVSS score: 9.8) - An insufficiently protected credentials vulnerability affecting multiple Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, and Logix Controllers that could allow an unauthorized user with network access to the controller to bypass the verification mechanism and authenticate with it, as well as alter its configuration and/or application code.

The addition of CVE-2017-7921 to the KEV catalog comes more than four months after the SANS Internet Storm Center disclosed that it had detected exploit attempts against Hikvision cameras susceptible to the flaw. However, there appears to be no public report describing attacks involving CVE-2021-22681.

In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to update to the latest supported software versions by March 26, 2026, as part of Binding Operational Directive (BOD) 22-01.

"These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," CISA said.

"Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practice."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/03/hikvision-and-rockwell-automation-cvss.html