← Back to browse · API

CVE-2021-22681

Severity
CRITICAL
CVSS
9.8
EPSS
0.60993
Risk score
85.55
CISA KEV
Yes
PoC
Yes
Published
2026-03-05
Modified
2026-03-05
First seen
2026-08-07
Aliases
EUVD-2021-9817, GHSA-PVH9-P4PW-H78Q
Products
Rockwell:Multiple Products, n/a:Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers Compact GuardLogix 5370, 5380, n/a:Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers CompactLogix 1768, 1769, 5370, 5380, 5480, n/a:Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers ControlLogix 5550, 5560, 5570, 5580, n/a:Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers DriveLogix 5560, 5730, 1794-L34, n/a:Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers GuardLogix 5570, 5580, n/a:Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers RSLogix 5000 Versions 16 through 20, n/a:Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers SoftLogix 5800, n/a:Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers Studio 5000 Logix Designer: Versions 21 and later
Sources
euvd EUVD-2021-9817
cisa.gov CVE-2021-22681
github 973dd87ae6bfce9ec4c6935b|CVE-2021-22681

Description

Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to verify Logix controllers are communicating with Rockwell Automation design software. If successfully exploited, this vulnerability could allow an unauthorized application to connect with Logix controllers. To leverage this vulnerability, an unauthorized user would require network access to the controller.

References