Vulnerability record · CVE-2021-22659 · published 25 March 2021
CVE-2021-22659: Rockwellautomation micrologix 1400 firmware classic buffer overflow vulnerability
Rockwellautomation · Micrologix 1400 Firmware
Rockwell Automation MicroLogix 1400 Version 21.6 and below may allow a remote unauthenticated attacker to send a specially crafted Modbus packet allowing the attacker to retrieve or modify random values in the register. If successfully exploited, this may lead to a buffer overflow resulting in a denial-of-service condition. The FAULT LED will flash RED and communications may be lost. Recovery from denial-of-service condition requires the fault to be cleared by the user.
Description
Rockwell Automation MicroLogix 1400 Version 21.6 and below may allow a remote unauthenticated attacker to send a specially crafted Modbus packet allowing the attacker to retrieve or modify random values in the register. If successfully exploited, this may lead to a buffer overflow resulting in a denial-of-service condition. The FAULT LED will flash RED and communications may be lost. Recovery from denial-of-service condition requires the fault to be cleared by the user.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1129877/loc/en_US#__highlight | Permissions RequiredVendor Advisory |
| https://us-cert.cisa.gov/ics/advisories/icsa-21-033-01 | Third Party AdvisoryUS Government Resource |
| https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1129877/loc/en_US#__highlight | Permissions RequiredVendor Advisory |
| https://us-cert.cisa.gov/ics/advisories/icsa-21-033-01 | Third Party AdvisoryUS Government Resource |
Track CVE-2021-22659 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-22659), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.