CRITICAL · 9.8

CVE-2021-22681

Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLo...

Vulnerability Description

Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
RockwellautomationFactorytalk Services Platform>= 2.10
RockwellautomationRslogix 5000>= 16, <= 20
RockwellautomationStudio 5000 Logix Designer>= 21.0
RockwellautomationCompact Guardlogix 5370-
RockwellautomationCompact Guardlogix 5380-
RockwellautomationCompactlogix 1768-
RockwellautomationCompactlogix 1769-
RockwellautomationCompactlogix 5370-
RockwellautomationCompactlogix 5380-
RockwellautomationCompactlogix 5480-
RockwellautomationControllogix 5550-
RockwellautomationControllogix 5560-
RockwellautomationControllogix 5570-
RockwellautomationControllogix 5580-
RockwellautomationDrivelogix 1794-L34-
RockwellautomationDrivelogix 5560-
RockwellautomationDrivelogix 5730-
RockwellautomationGuardlogix 5570-
RockwellautomationGuardlogix 5580-
RockwellautomationSoftlogix 5800-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-22681?

CVE-2021-22681 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLo...

How severe is CVE-2021-22681?

CVE-2021-22681 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-22681?

Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Factorytalk Services Platform, Rockwellautomation Rslogix 5000, Rockwellautomation Studio 5000 Logix Designer, Rockwellautomation Compact Guardlogix 5370, Rockwellautomation Compact Guardlogix 5380.