CVE detail
CVE-2021-22681
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 25.6 · diversity 16.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 2
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
12 source links · newest first
. Default or weak credentials on internet-exposed hardware, and suddenly operators are locked out of their own systems. CVE-2021-22681 is a critical Rockwell Automation vulnerability (CVSS 9.8) that remained unexploited for years because industrial control systems are difficult to patch without disrupting essential services. Since March 2026, however,
newssecurityaffairs.comAug 2, 2026, 5:06 AMon for the first time, and added detection guidance for manipulation of reusable code modules embedded in PLC programs. CVE-2021-22681 (CVSS 9.8), a critical authentication bypass in Rockwell Automation Logix controllers with no available vendor patch, was added to CISA's Known Exploited Vulnerabilities catalog in March 2026 following confirmed exploit
vendorwww.tenable.comJul 29, 2026, 3:19 AMer new nor sophisticated; they're just unaddressed. For example, recent Iran-linked attacks in the US likely weaponized CVE-2021-22681 , a 5-year-old vulnerability. Prioritize patching and hardening external-facing assets first, then work to critical systems and similar. For OT and related technologies, take advantage of maintenance cycles and similar
newswww.darkreading.comJul 9, 2026, 8:32 PMThe industrial automation giant has fixed security holes in Logix, CompactLogix, Flex, RSLinx, and FactoryTalk products.
newswww.securityweek.comJun 17, 2026, 11:32 AMThe vulnerability was disclosed and mitigated in 2021 but its in-the-wild exploitation has only now come to light.
newswww.securityweek.comMar 6, 2026, 12:32 PM- U.S. CISA adds Apple, Rockwell, and Hikvision flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple, Rockwell, and Hikvision flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Apple, Rockwell, and Hikvision flaws to its Known Exploited Vulnerabilities (KEV) catalog. Below are the flaws added to the catalog: CVE-2023-43000 is a use-after-free issue in the WebKit component. Apple […]
newssecurityaffairs.comMar 6, 2026, 8:42 AM Rockwell Automation is concerned about internet-exposed ICS due to heightened geopolitical tensions and adversarial cyber activity globally.
newswww.securityweek.comMay 22, 2024, 1:16 PM- Week in review: Exchange Servers under attack, disinformation economics, Patch Tuesday forecastHelp Net Security
Here’s an overview of some of last week’s most interesting news and articles: How do I select a cloud security solution for my business? To select a suitable cloud security solution for your business, you need to think about a variety of factors. We’ve talked to several industry professionals to get their insight on the topic. Critical flaw in Rockwell PLCs allows attackers to fiddle with them (CVE-2021-22681) A critical, easy to exploit vulnerability (CVE-2021-22681) … More →
newswww.helpnetsecurity.comMar 7, 2021, 9:01 AM - March 1st – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 1st March, please download our Threat Intelligence Bulletin. Top Attacks and Breaches The biochemical systems at an Oxford university research lab currently studying the Covid-19 pandemic has been breached. Clinical research was not affected by the incident. Breached systems include machines used to prepare […]
vendorresearch.checkpoint.comMar 1, 2021, 3:49 PM - Critical flaw in Rockwell PLCs allows attackers to fiddle with them (CVE-2021-22681)Help Net Security
A critical, easy to exploit vulnerability (CVE-2021-22681) may allow attackers to remotely connect to a number of Rockwell Automation’s programmable logic controllers (PLCs) and to install new (malicious) firmware, alter the device’s configuration, and so on. Due to these factors the vulnerability has received the maximum CVSS v3 severity score – 10.0. About the vulnerability (CVE-2021-22681) Rockwell Automation’s PLCs are used around the world to control industrial equipment. The flaw may allow an attacker to … More →
newswww.helpnetsecurity.comMar 1, 2021, 12:02 PM A critical authentication bypass vulnerability could be exploited by remote attackers to Rockwell Automation programmable logic controllers (PLCs). A critical authentication bypass vulnerability, tracked as CVE-2021-22681, can be exploited by remote attackers to compromise programmable logic controllers (PLCs) manufactured by Rockwell Automation. The vulnerability was independently reported to Rockwell by researchers at the Soonchunhyang University […]
newssecurityaffairs.comFeb 27, 2021, 9:48 PMIndustrial organizations have been warned this week that a critical authentication bypass vulnerability can allow hackers to remotely compromise programmable logic controllers (PLCs) made by industrial automation giant Rockwell Automation.
newswww.securityweek.comFeb 26, 2021, 11:54 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2022-1797CVSS 6.8 · Medium
A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix Controllers, resulting in a ma…
- CVE-2024-8626CVSS 8.7 · High
Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multi…
- CVE-2024-5659CVSS 8.3 · High
Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnera…
- CVE-2024-3493CVSS 8.6 · High
A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (…
- CVE-2022-3157CVSS 8.6 · High
A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (…
- CVE-2022-1159CVSS 7.7 · High
Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation running Studio 5000 Logix Designer…