CVE-2021-22681

Confirmed PUBLISHED

Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers...

Rockwell Automation · Studio 5000 Logix Designer, RSLogix 5000

1 day faster than CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical EPSS 25.5%

At a Glance

Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.

cisa
CVE Published
Mar 03, 2021
Exploitation Reported
Jun 01, 2026
CVSS
9.8 Critical
EPSS
25.5%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
n/a
Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers

RSLogix 5000 Versions 16 through 20

Affected
n/a
Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers

Studio 5000 Logix Designer: Versions 21 and later

Affected
n/a
Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers

CompactLogix 1768, 1769, 5370, 5380, 5480

Affected
n/a
Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers

ControlLogix 5550, 5560, 5570, 5580

Affected
n/a
Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers

DriveLogix 5560, 5730, 1794-L34

Affected
n/a
Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers

Compact GuardLogix 5370, 5380

Affected
n/a
Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers

GuardLogix 5570, 5580

Affected
n/a
Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers

SoftLogix 5800

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.