Skip to main content
CISA Known Exploited Vulnerabilities

Rockwell Multiple Products Insufficient Protected Credentials Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.

Added to KEV
2026-03-05
Remediation due
2026-03-26

Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA notes
https://support.rockwellautomation.com/app/answers/answer_view/a_id/1130301/~/cve-2021-22681%3A-authentication-bypass-vulnerability-found-in-logix-controllers- ; https://www.cisa.gov/news-events/ics-advisories/icsa-21-056-03 ; https://nvd.nist.gov/vuln/detail/CVE-2021-22681

Description

Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.

Severity

CVSS 3.1 · CISA9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC · CISA-ADP
Exploitationactive
Automatableyes
Technical impacttotal

Affected Products

VendorProductAffected versions
-Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers
RSLogix 5000 Versions 16 through 20
Studio 5000 Logix Designer: Versions 21 and later
CompactLogix 1768, 1769, 5370, 5380, 5480
ControlLogix 5550, 5560, 5570, 5580
DriveLogix 5560, 5730, 1794-L34
Compact GuardLogix 5370, 5380
GuardLogix 5570, 5580
SoftLogix 5800

References

1 Links

Record Details

Published
2021-03-03
Last updated
2026-03-06
Assigner (CNA)
icscert
Credited to
-

Related Tool Categories

Tool categories that test for or protect against this vulnerability class.

CWE-522 · Insufficiently Protected Credentials

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.