Rockwell Multiple Products Insufficient Protected Credentials Vulnerability - Active in CISA KEV catalog.
Description
Rockwell Multiple Products Insufficient Protected Credentials Vulnerability - Active in CISA KEV catalog.
AI Analyst Comment
Remediation
FEDERAL DEADLINE: March 25, 2026 (20 days). Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. FEDERAL DEADLINE: March 25, 2026 (20 days). Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA KEV Details
Deadline: March 25, 2026
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Description Summary:
An unauthenticated remote attacker can bypass the verification mechanism between Rockwell Automation design software and Logix controllers, leading to unauthorized access and potential control manipulation.
Executive Summary:
This critical authentication bypass vulnerability in Rockwell Automation control systems is currently being exploited in the wild and poses a severe risk to industrial operations.
Vulnerability Details
CVE-ID: CVE-2021-22681
Affected Software: Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, and Logix Controllers
Affected Versions: Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, RSLogix 5000 Versions 16 through 20, and various Logix controllers including CompactLogix 1768, 1769, 5370, 5380, 5480; ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; and SoftLogix 5800.
Vulnerability: The vulnerability exists due to insufficiently protected credentials used to verify communication between design software and controllers. An unauthenticated attacker can bypass this verification process to gain unauthorized access to the target devices.
Business Impact
The severity of this flaw is reflected in its CVSS score of 9.5, which indicates a critical risk. Successful exploitation allows an attacker to gain unauthorized control over industrial controllers, which can lead to the manipulation of PLC logic, unauthorized process changes, or complete system disruption. In an industrial or manufacturing environment, this could result in significant safety risks, production downtime, and potential physical damage to equipment.
Remediation Plan
Immediate Action: Review the vendor advisory at https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and apply all recommended mitigations or firmware updates provided by Rockwell Automation immediately.
Proactive Monitoring: Monitor network traffic for unauthorized access attempts directed at industrial control protocols and look for anomalous communication patterns between engineering workstations and controller hardware.
Compensating Controls: Implement strict network segmentation to isolate industrial control networks from enterprise and internet-facing segments to limit the attack surface. Use firewalls to restrict access to controller ports and interfaces to only authorized workstations.
Exploitation Status
Public Exploit Available: Yes, a public proof-of-concept exists as evidenced by available repositories and documentation.
Analyst Notes: This vulnerability is confirmed to be actively exploited in the wild as of March 5, 2026. The reliance on insufficiently protected credentials makes this a high-value target for attackers looking to disrupt industrial processes.
Analyst Recommendation
Given the confirmed active exploitation and the critical nature of the affected systems, immediate attention is required. Security teams must prioritize identifying all instances of the affected Rockwell Automation software and controllers within their environment. Apply all vendor-recommended mitigations as a matter of urgency to prevent unauthorized access and potential operational impact.