Junglewise Threat Intelligence

CVE-2021-22681: Rockwell Automation Logix Designer authentication bypass in Logix Controllers

CVE-2021-22681 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-03-05

Technologies: Rockwell Automation Studio 5000 Logix Designer, Apple Multiple Products. Vendors: Rockwell Automation, Apple.

Executive brief

Multiple Rockwell Automation industrial controllers and design software products contain a critical security flaw that allows unauthorized users to bypass authentication. These systems are used to control and monitor industrial processes in manufacturing and infrastructure. If exploited, an attacker could gain full control over the industrial hardware, potentially leading to operational disruption, physical damage, or safety risks.

Technical details

The vulnerability (CWE-522) exists because Rockwell Automation Studio 5000 Logix Designer and RSLogix 5000 use a static or insufficiently protected key to verify communications with Logix controllers. An unauthenticated attacker with network access to the controller can discover this key and use it to bypass the verification mechanism. This allows the attacker to authenticate with the controller as if they were using authorized design software. Successful exploitation grants the attacker the ability to modify controller configurations or logic. This vulnerability has been observed being exploited in the wild.

Affected products

  • Rockwell Automation Studio 5000 Logix Designer 21 and later
  • Rockwell Automation RSLogix 5000 16 through 20
  • Rockwell Automation CompactLogix (1768, 1769, 5370, 5380, 5480)
  • Rockwell Automation ControlLogix (5550, 5560, 5570, 5580)
  • Rockwell Automation GuardLogix (5570, 5580)
  • Rockwell Automation DriveLogix (5560, 5730, 1794-L34)
  • Rockwell Automation SoftLogix 5800

Timeline

  • 2021-02-25: advisory: Initial ICSA-21-056-03 advisory published
  • 2026-03-05: kev added: Added to CISA Known Exploited Vulnerabilities catalog

Related threats