CVE-2021-22681
9.5 CISA KEVRockwell Automation · Studio 5000 Logix Designer, RSLogix 5000, and various Logix controllers
An unauthenticated remote attacker can bypass the verification mechanism between Rockwell Automation design software and Logix controllers, leading to unauthorized access and potential control manipulation.
Executive summary
This critical authentication bypass vulnerability in Rockwell Automation control systems is currently being exploited in the wild and poses a severe risk to industrial operations.
Vulnerability
The vulnerability exists due to insufficiently protected credentials used to verify communication between design software and controllers. An unauthenticated attacker can bypass this verification process to gain unauthorized access to the target devices.
Business impact
The severity of this flaw is reflected in its CVSS score of 9.5, which indicates a critical risk. Successful exploitation allows an attacker to gain unauthorized control over industrial controllers, which can lead to the manipulation of PLC logic, unauthorized process changes, or complete system disruption. In an industrial or manufacturing environment, this could result in significant safety risks, production downtime, and potential physical damage to equipment.
Remediation
Immediate Action: Review the vendor advisory at https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and apply all recommended mitigations or firmware updates provided by Rockwell Automation immediately.
Proactive Monitoring: Monitor network traffic for unauthorized access attempts directed at industrial control protocols and look for anomalous communication patterns between engineering workstations and controller hardware.
Compensating Controls: Implement strict network segmentation to isolate industrial control networks from enterprise and internet-facing segments to limit the attack surface. Use firewalls to restrict access to controller ports and interfaces to only authorized workstations.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as evidenced by available repositories and documentation.
Analyst recommendation
Given the confirmed active exploitation and the critical nature of the affected systems, immediate attention is required. Security teams must prioritize identifying all instances of the affected Rockwell Automation software and controllers within their environment. Apply all vendor-recommended mitigations as a matter of urgency to prevent unauthorized access and potential operational impact.