Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-22681


Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.


Published

2021-03-03T18:15:14.643

Last Modified

2024-11-21T05:50:28.110

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-522
  • Type: Primary
    CWE-522

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rockwellautomation factorytalk_services_platform ≥ 2.10 Yes
Application rockwellautomation rslogix_5000 ≤ 20 Yes
Application rockwellautomation studio_5000_logix_designer ≥ 21.0 Yes
Hardware rockwellautomation compact_guardlogix_5370 - No
Hardware rockwellautomation compact_guardlogix_5380 - No
Hardware rockwellautomation compactlogix_1768 - No
Hardware rockwellautomation compactlogix_1769 - No
Hardware rockwellautomation compactlogix_5370 - No
Hardware rockwellautomation compactlogix_5380 - No
Hardware rockwellautomation compactlogix_5480 - No
Hardware rockwellautomation controllogix_5550 - No
Hardware rockwellautomation controllogix_5560 - No
Hardware rockwellautomation controllogix_5570 - No
Hardware rockwellautomation controllogix_5580 - No
Hardware rockwellautomation drivelogix_1794-l34 - No
Hardware rockwellautomation drivelogix_5560 - No
Hardware rockwellautomation drivelogix_5730 - No
Hardware rockwellautomation guardlogix_5570 - No
Hardware rockwellautomation guardlogix_5580 - No
Hardware rockwellautomation softlogix_5800 - No

References