Skip to main content

CVE detail

CVE-2021-22681

Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.

CVSS 9.8 · CriticalBuzz score 66.7KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 66.7

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 25.6 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
25.6
12 evidence mentions in the snapshot
Diversity score
16.0
6 sources across 2 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
2
within the 30d window
Peak daily
1
highest bucket

Evidence

Source links by recency

Newest mentions first
12 source links · newest first
  • . Default or weak credentials on internet-exposed hardware, and suddenly operators are locked out of their own systems. CVE-2021-22681 is a critical Rockwell Automation vulnerability (CVSS 9.8) that remained unexploited for years because industrial control systems are difficult to patch without disrupting essential services. Since March 2026, however,

    newssecurityaffairs.comAug 2, 2026, 5:06 AM
  • on for the first time, and added detection guidance for manipulation of reusable code modules embedded in PLC programs. CVE-2021-22681 (CVSS 9.8), a critical authentication bypass in Rockwell Automation Logix controllers with no available vendor patch, was added to CISA's Known Exploited Vulnerabilities catalog in March 2026 following confirmed exploit

    vendorwww.tenable.comJul 29, 2026, 3:19 AM
  • er new nor sophisticated; they're just unaddressed. For example, recent Iran-linked attacks in the US likely weaponized CVE-2021-22681 , a 5-year-old vulnerability. Prioritize patching and hardening external-facing assets first, then work to critical systems and similar. For OT and related technologies, take advantage of maintenance cycles and similar

    newswww.darkreading.comJul 9, 2026, 8:32 PM
  • The industrial automation giant has fixed security holes in Logix, CompactLogix, Flex, RSLinx, and FactoryTalk products.

    newswww.securityweek.comJun 17, 2026, 11:32 AM
  • The vulnerability was disclosed and mitigated in 2021 but its in-the-wild exploitation has only now come to light.

    newswww.securityweek.comMar 6, 2026, 12:32 PM
  • U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple, Rockwell, and Hikvision flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple, Rockwell, and Hikvision flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: CVE-2023-43000 is a use-after-free issue in the WebKit component. Apple […]

    newssecurityaffairs.comMar 6, 2026, 8:42 AM
  • Rockwell Automation is concerned about internet-exposed ICS due to heightened geopolitical tensions and adversarial cyber activity globally.

    newswww.securityweek.comMay 22, 2024, 1:16 PM
  • Here’s an overview of some of last week’s most interesting news and articles: How do I select a cloud security solution for my business? To select a suitable cloud security solution for your business, you need to think about a variety of factors. We’ve talked to several industry professionals to get their insight on the topic. Critical flaw in Rockwell PLCs allows attackers to fiddle with them (CVE-2021-22681) A critical, easy to exploit vulnerability (CVE-2021-22681) … More →

    newswww.helpnetsecurity.comMar 7, 2021, 9:01 AM
  • March 1st – Threat Intelligence ReportCheck Point Research

    For the latest discoveries in cyber research for the week of 1st March, please download our Threat Intelligence Bulletin. Top Attacks and Breaches The biochemical systems at an Oxford university research lab currently studying the Covid-19 pandemic has been breached. Clinical research was not affected by the incident. Breached systems include machines used to prepare […]

    vendorresearch.checkpoint.comMar 1, 2021, 3:49 PM
  • A critical, easy to exploit vulnerability (CVE-2021-22681) may allow attackers to remotely connect to a number of Rockwell Automation’s programmable logic controllers (PLCs) and to install new (malicious) firmware, alter the device’s configuration, and so on. Due to these factors the vulnerability has received the maximum CVSS v3 severity score – 10.0. About the vulnerability (CVE-2021-22681) Rockwell Automation’s PLCs are used around the world to control industrial equipment. The flaw may allow an attacker to … More →

    newswww.helpnetsecurity.comMar 1, 2021, 12:02 PM
  • A critical authentication bypass vulnerability could be exploited by remote attackers to Rockwell Automation programmable logic controllers (PLCs). A critical authentication bypass vulnerability, tracked as CVE-2021-22681, can be exploited by remote attackers to compromise programmable logic controllers (PLCs) manufactured by Rockwell Automation. The vulnerability was independently reported to Rockwell by researchers at the Soonchunhyang University […]

    newssecurityaffairs.comFeb 27, 2021, 9:48 PM
  • Industrial organizations have been warned this week that a critical authentication bypass vulnerability can allow hackers to remotely compromise programmable logic controllers (PLCs) made by industrial automation giant Rockwell Automation.

    newswww.securityweek.comFeb 26, 2021, 11:54 AM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence