LIVE NEWSROOM · --:-- · May 24, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2021-22681

CVE-2021-22681

Rockwell Multiple Products Insufficient Protected Credentials Vulnerability

CVSS 9.8 · CRITICAL ⚠ CISA KEV — ACTIVELY EXPLOITED
On the CISA KEV catalog

Confirmed exploited in the wild. Added 2026-03-05. Federal remediation due 2026-03-26.
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Summary

Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.

CVSS 3.1 breakdown

Base score9.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vectorNETWORK
Attack complexityLOW
Privileges requiredNONE
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityHIGH

Weakness type (CWE)

Affected products

Rockwellautomation factorytalk services platformRockwellautomation rslogix 5000Rockwellautomation studio 5000 logix designerRockwellautomation compact guardlogix 5370Rockwellautomation compact guardlogix 5380Rockwellautomation compactlogix 1768Rockwellautomation compactlogix 1769Rockwellautomation compactlogix 5370Rockwellautomation compactlogix 5380Rockwellautomation compactlogix 5480Rockwellautomation controllogix 5550Rockwellautomation controllogix 5560Rockwellautomation controllogix 5570Rockwellautomation controllogix 5580Rockwellautomation drivelogix 1794-l34Rockwellautomation drivelogix 5560Rockwellautomation drivelogix 5730Rockwellautomation guardlogix 5570Rockwellautomation guardlogix 5580Rockwellautomation softlogix 5800
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD + CISA KEV. NVD last modified 2026-03-06. Always verify against the vendor advisory before acting.

Scroll to Top