← Vulnerability feed

Vulnerability record · CVE-2021-22681 · published 3 March 2021

CVE-2021-22681: Rockwell Logix Designer authentication bypass via weak key verification

Rockwellautomation · Factorytalk Services Platform

Rockwell Automation Studio 5000 Logix Designer (v21+) and RSLogix 5000 (v16-20) rely on a key to verify that Logix controllers are talking to genuine Rockwell software. An unauthenticated attacker can bypass that verification mechanism and authenticate to a wide range of CompactLogix, ControlLogix, DriveLogix, GuardLogix and SoftLogix controllers. Because the flaw defeats the trust check between engineering software and controllers, it undermines the integrity of industrial control programming and is listed in CISA's KEV catalog.

9.8 CVSS 3.1 Critical CISA KEV since 5 Mar 2026 EPSS 64% · top 0.8% CWE-522 · Insufficiently protected credentials
9.8CVSS 3.1 base score, v2 7.5
64%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 with network reachability, no authentication, full confidentiality/integrity/availability impact, and confirmed inclusion in CISA's KEV catalog.

What it is

Rockwell Automation Studio 5000 Logix Designer (v21+) and RSLogix 5000 (v16-20) rely on a key to verify that Logix controllers are talking to genuine Rockwell software. An unauthenticated attacker can bypass that verification mechanism and authenticate to a wide range of CompactLogix, ControlLogix, DriveLogix, GuardLogix and SoftLogix controllers. Because the flaw defeats the trust check between engineering software and controllers, it undermines the integrity of industrial control programming and is listed in CISA's KEV catalog.

Impact

An attacker gains authenticated access to affected Logix controllers, enabling unauthorized reads and writes to controller logic and configuration with high confidentiality, integrity and availability impact. In an ICS environment this can translate to process manipulation or disruption.

Attack surface

Reachable over the network (CVSS vector AV:N) with no privileges and no user interaction required; the attacker only needs network access to the controller or engineering workstation path. No authentication is needed because the bypass is the authentication check itself.

Exploitation

CISA added this CVE to the Known Exploited Vulnerabilities catalog with a remediation due date of 2026-03-26, indicating known exploitation in the wild. EPSS gives a 30-day exploitation probability of roughly 0.64 (99th percentile), and no ransomware campaign use is documented.

What to do

  • Apply the vendor mitigations in CISA ICS advisory ICSA-21-056-03 and upgrade Studio 5000 Logix Designer and RSLogix 5000 to fixed versions.
  • Follow BOD 22-01 guidance; if mitigations are unavailable, discontinue use of the affected product.
  • Segment and firewall Logix controllers so only trusted engineering workstations can reach them, and block controller access from untrusted networks.
  • Restrict and monitor engineering workstation access, and enforce least privilege for anyone who can program controllers.
  • Review controller key/credential handling and rotate any exposed keys where the vendor supports it.

Detection

  • Monitor network traffic to Logix controllers for unexpected or unauthorized engineering connections and authentication attempts.
  • Alert on controller program downloads, key changes or logic modifications outside approved change windows.
  • Audit engineering workstation logs for Studio 5000 or RSLogix 5000 sessions originating from unexpected hosts or accounts.
  • Correlate controller access events with asset inventory to flag connections from non-engineering or non-allowlisted systems.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-22681 to the Known Exploited Vulnerabilities catalog on 5 March 2026 as "Rockwell Multiple Products Insufficient Protected Credentials Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 26 March 2026.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-22681 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2020-14516Rockwellautomation factorytalk services platform vulnerabilityIn Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing a…EPSS 4.1%9.8CVE-2020-6967Rockwellautomation factorytalk services platform deserialization of untrusted data vulnerabilityIn Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, FactoryTalk Diagnostics ex…EPSS 5.5%9.1CVE-2024-21917Rockwellautomation factorytalk services platform improper verification of cryptographic signature vulnerabilityA vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for a…EPSS 0.86%8.8CVE-2024-21915Rockwellautomation factorytalk services platform incorrect permission assignment vulnerabilityA privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic us…EPSS 0.99%8.8CVE-2021-32960Rockwellautomation factorytalk services platform incorrect authorization vulnerabilityRockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that ma…EPSS 2.4%8.8CVE-2020-12033Rockwellautomation factorytalk services platform improper input validation vulnerabilityIn Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not validate supplied identifiers…EPSS 1.1%8.2CVE-2020-12034Rockwellautomation eds subsystem sql injection vulnerabilityProducts that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterprise): Versions 6.00, 6.10, and …EPSS 1.3%8.1CVE-2023-46290Rockwellautomation factorytalk services platform improper authentication vulnerabilityDue to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTal…EPSS 2.7%

Source: NIST National Vulnerability Database (record CVE-2021-22681), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.