CVE-2021-22681
Description
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.
Summary dbcve.org
This is an authentication bypass vulnerability in Rockwell Automation's Studio 5000 Logix Designer and RSLogix 5000 software. The software uses a verification key to ensure Logix controllers are communicating with legitimate Rockwell Automation devices. An unauthenticated remote attacker can bypass this verification mechanism and authenticate with affected controller families including CompactLogix, ControlLogix, GuardLogix, DriveLogix, and SoftLogix controllers.
Mitigation
Immediately update to the latest patched versions of Studio 5000 Logix Designer and RSLogix 5000 per vendor advisories. Implement network segmentation to isolate industrial control systems and restrict external access to affected devices.