← Back to CVE List
Vulnerability Intelligence Report
Rockwell Multiple Products Insufficient Protected Credentials Vulnerability

CVE-2021-22681

Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.

CISA KEV SSVC: Active Exploitation Automatable
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
EPSS Probability:25.45%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-522 ↗Insufficiently Protected Credentials CWE-522

Affected Products & Versions

Vendor Product Affected Versions
rockwellautomation factorytalk_services_platform all
rockwellautomation rslogix_5000 all
rockwellautomation studio_5000_logix_designer all
rockwellautomation compact_guardlogix_5370 all
rockwellautomation compact_guardlogix_5380 all
rockwellautomation compactlogix_1768 all
rockwellautomation compactlogix_1769 all
rockwellautomation compactlogix_5370 all
rockwellautomation compactlogix_5380 all
rockwellautomation compactlogix_5480 all
rockwellautomation controllogix_5550 all
rockwellautomation controllogix_5560 all
rockwellautomation controllogix_5570 all
rockwellautomation controllogix_5580 all
rockwellautomation drivelogix_1794-l34 all
rockwellautomation drivelogix_5560 all
rockwellautomation drivelogix_5730 all
rockwellautomation guardlogix_5570 all
rockwellautomation guardlogix_5580 all
rockwellautomation softlogix_5800 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
25.455%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCybersecurity and Infrastructure Security Agency (CISA) Industrial Control Systems (ICS) · CERT · USA
Reserved2021-01-05T00:00:00
Published2021-03-03T17:59:43
Last Updated2026-03-06T05:01:20

LINK COPIED TO CLIPBOARD