CRITICAL

CVE-2021-22681

Rockwellautomation Factorytalk Services Platform 2021-03-03 CVSS v3.1
CVSS
9.8
KEV

Description

Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.

Summary dbcve.org

This is an authentication bypass vulnerability in Rockwell Automation's Studio 5000 Logix Designer and RSLogix 5000 software. The software uses a verification key to ensure Logix controllers are communicating with legitimate Rockwell Automation devices. An unauthenticated remote attacker can bypass this verification mechanism and authenticate with affected controller families including CompactLogix, ControlLogix, GuardLogix, DriveLogix, and SoftLogix controllers.

Mitigation

Immediately update to the latest patched versions of Studio 5000 Logix Designer and RSLogix 5000 per vendor advisories. Implement network segmentation to isolate industrial control systems and restrict external access to affected devices.

Weakness (CWE)

CWE-522 Insufficiently Protected Credentials

EPSS Score

63.63%
Probability of exploitation in next 30 days
99.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE