Critical flaw in Rockwell PLCs allows attackers to fiddle with them (CVE-2021-22681)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-22681 | Authentication Bypass in Rockwell Automation Studio 5000 Logix Designer and Logix PLCs Rockwell Automation's Studio 5000 Logix Designer (versions 21 and later) and RSLogix 5000 (versions 16 through 20) use a shared key to verify that they are communicating with genuine Allen-Bradley Logix controllers, and an unauthenticated remote attacker can bypass this verification mechanism (CWE-522, insufficient protection of credentials). The attack requires only network access to the affected software or controllers - no credentials, no user interaction, and no special conditions (CVSS 3.1: 9.8). By bypassing the verification, an attacker can authenticate to CompactLogix, ControlLogix, DriveLogix, Compact GuardLogix, GuardLogix and SoftLogix controllers and interact with the PLCs, potentially tampering with industrial processes. Any deployment running the affected engineering software versions with the listed Logix controller families is in scope, which spans a very large share of Rockwell's installed base. CISA added this flaw to its Known Exploited Vulnerabilities catalog on 2026-03-05 (ransomware use unknown), and EPSS puts the 30-day exploitation probability at roughly 64%; no public proof-of-concept is known. Do: Apply mitigations per Rockwell's instructions - the vendor has advised disconnecting internet-facing connections, so remove internet exposure from affected controllers and engineering workstations and segment OT networks. Follow applicable CISA BOD 22-01 guidance, and inventory for Studio 5000 Logix Designer v21+ or RSLogix 5000 v16-20 used with the listed controllers; upgrade per vendor guidance or discontinue use if mitigations are unavailable. | 9.8 | 64% | KEV |
| massroughly 1 million or more Logix controller installations (tens of thousands likely internet-exposed) |
Full article325 words · extracted from helpnetsecurity.com · click to collapse
A critical, easy to exploit vulnerability (CVE-2021-22681) may allow attackers to remotely connect to a number of Rockwell Automation’s programmable logic controllers (PLCs) and to install new (malicious) firmware, alter the device’s configuration, and so on. Due to these factors the vulnerability has received the maximum CVSS v3 severity score – 10.0.

About the vulnerability (CVE-2021-22681)
Rockwell Automation’s PLCs are used around the world to control industrial equipment. The flaw may allow an attacker to discover the cryptographic key used to verify communication between Rockwell Logix controllers and their engineering stations.
“An attacker with this key could mimic a workstation and therefore be able to manipulate configurations or code running on the PLC (upload/download logic), and directly impact a manufacturing process,” Claroty researchers explained.
CVE-2021-22681 affects several series of the company’s Logix controllers:
- CompactLogix 1768, 1769, 5370, 5380 and 5480
- ControlLogix 5550, 5560, 5570 and 5580
- DriveLogix 5560, 5730 and 1794-L34
- Compact GuardLogix 5370 and 5380
- GuardLogix 5570 and 5580
- SoftLogix 5800
In effect, all devices running RSLogix 5000 (versions 16 through 20) and Studio 5000 Logix Designer (versions 21 and later) are vulnerable.
What to do?
The vulnerability has been independently discovered by Claroty, Kaspersky Lab, and researchers from South Korea’s Soonchunhyang University’s Lab of Information Systems Security Assurance.
The good news is that, according to the U.S. CISA, there are no known public exploits that specifically target this authentication bypass flaw.
There is no fix available, but Rockwell Automation advises administrators to implement specific mitigations (e.g., putting the vulnerable controller’s mode switch to “Run” mode, deploying CIP Security – an open-standard secure communication mechanism for EtherNet/IP networks – for Logix Designer connections) and more generic ones (network segmentation, additional security controls such isolating devices from other networks and the internet, secure remote access).
They also offered advice on how admins can detect any changes that attackers may have made to configuration or application files. (The CISA advisory holds more information.)
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/03/01/cve-2021-22681/