← Vulnerability feed

Vulnerability record · CVE-2021-33012 · published 9 July 2021

CVE-2021-33012: Rockwellautomation micrologix 1100 firmware improper input validation vulnerability

Rockwellautomation · Micrologix 1100 Firmware

Rockwell Automation MicroLogix 1100, all versions, allows a remote, unauthenticated attacker sending specially crafted commands to cause the PLC to fault when the controller is switched to RUN mode, which results in a denial-of-service condition. If successfully exploited, this vulnerability will cause the controller to fault whenever the controller is switched to RUN mode.

8.6 CVSS 3.1 High EPSS 2.6% · top 15.0% CWE-20 · Improper input validation
8.6CVSS 3.1 base score, v2 5.0
2.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Rockwell Automation MicroLogix 1100, all versions, allows a remote, unauthenticated attacker sending specially crafted commands to cause the PLC to fault when the controller is switched to RUN mode, which results in a denial-of-service condition. If successfully exploited, this vulnerability will cause the controller to fault whenever the controller is switched to RUN mode.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://us-cert.cisa.gov/ics/advisories/icsa-21-189-01 Third Party AdvisoryUS Government Resource
https://us-cert.cisa.gov/ics/advisories/icsa-21-189-01 Third Party AdvisoryUS Government Resource

Track CVE-2021-33012 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-6990Rockwellautomation micrologix 1400 a firmware hard-coded credentials vulnerabilityRockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix…EPSS 4.4%9.8CVE-2015-6490Rockwellautomation micrologix 1100 firmware memory buffer overflow vulnerabilityStack-based buffer overflow on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices through B FRN 15.003 allows remote attacker…EPSS 7.0%7.5CVE-2022-3166Rockwellautomation micrologix 1100 firmware vulnerabilityRockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers contain a vulnerability that may lead to a denial-…EPSS 0.70%7.5CVE-2020-6984Rockwellautomation micrologix 1400 a firmware broken cryptographic algorithm vulnerabilityRockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix…EPSS 2.8%7.5CVE-2020-6988Rockwellautomation micrologix 1400 a firmware improper authentication vulnerabilityRockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix…EPSS 4.0%7.5CVE-2015-6492Rockwellautomation micrologix 1100 firmware memory buffer overflow vulnerabilityAllen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allow remote attackers to cause a denial of service (m…EPSS 4.5%6.5CVE-2022-2179Rockwellautomation micrologix 1100 firmware clickjacking vulnerabilityThe X-Frame-Options header in Rockwell Automation MicroLogix 1100/1400 Versions 21.007 and prior is not configured in the HTTP response, which could …EPSS 1.2%6.5CVE-2015-6486Rockwellautomation micrologix 1100 firmware sql injection vulnerabilitySQL injection vulnerability on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allows remote authentic…EPSS 4.3%

Source: NIST National Vulnerability Database (record CVE-2021-33012), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.