CVE-2021-22681Active Exploitation(rockwellautomation / compact_guardlogix_5370)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 11 mentions and remains active

Immediate actions

  • Patch rockwellautomation compact_guardlogix_5370 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts

Recommended action window: Immediate (within 24h)

NVD description

Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.

7.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-03-26. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-522

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • compact_guardlogix_5370
  • compact_guardlogix_5380
  • compactlogix_1768
  • compactlogix_1769

Threat summary

  • Active exploitation appears in 30 classified signals
  • Exploit tooling references are present in monitored signal
  • Patch or workaround signal is available
  • 40 mentions across 20 observed days

What's happening

  • Active exploitation reported across 30 signals
  • Exploit tool or code specified in 2 signals
  • Patch or workaround mentioned in 15 signals
  • Technical details provided in 18 signals
  • General: 5 classified signals
  • Peaked 18d ago at 11 mentions (2026-03-06); latest day: 1
  • 40 total mentions across 20 days

Affected systems

Products
compact_guardlogix_5370compact_guardlogix_5380compactlogix_1768compactlogix_1769compactlogix_5370compactlogix_5380compactlogix_5480controllogix_5550controllogix_5560controllogix_5570

1 version affected across 20 products

Deep dive

Activity timeline40 mentions / 20d
036811Mentions · 2026-03-05: 2Mentions · 2026-03-06: 11Mentions · 2026-03-07: 4Mentions · 2026-03-08: 1Mentions · 2026-03-09: 1Mentions · 2026-03-12: 1Mentions · 2026-03-15: 2Mentions · 2026-03-17: 1Mentions · 2026-04-07: 1Mentions · 2026-04-09: 1Mentions · 2026-04-10: 2Mentions · 2026-04-15: 1Mentions · 2026-04-17: 1Mentions · 2026-04-19: 1Mentions · 2026-04-30: 1Mentions · 2026-07-31: 2Mentions · 2026-08-02: 1Mentions · 2026-08-04: 4Mentions · 2026-08-06: 1Mentions · 2026-09-06: 1Exploit Tool / Code · 2026-03-06: 1Exploit Tool / Code · 2026-04-30: 1Active Exploitation · 2026-03-05: 1Active Exploitation · 2026-03-06: 10Active Exploitation · 2026-03-07: 3Active Exploitation · 2026-03-08: 1Active Exploitation · 2026-03-09: 1Active Exploitation · 2026-03-12: 1Active Exploitation · 2026-03-15: 1Active Exploitation · 2026-03-17: 1Active Exploitation · 2026-04-07: 1Active Exploitation · 2026-04-09: 1Active Exploitation · 2026-04-10: 2Active Exploitation · 2026-04-17: 1Active Exploitation · 2026-04-19: 1Active Exploitation · 2026-04-30: 1Active Exploitation · 2026-07-31: 1Active Exploitation · 2026-08-02: 1Active Exploitation · 2026-08-06: 1Active Exploitation · 2026-09-06: 1Patch / Workaround · 2026-03-06: 5Patch / Workaround · 2026-03-07: 2Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-30: 1Patch / Workaround · 2026-08-02: 1Patch / Workaround · 2026-08-04: 2Technical Details · 2026-03-06: 7Technical Details · 2026-03-07: 2Technical Details · 2026-03-08: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-15: 1Technical Details · 2026-03-17: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-10: 1Technical Details · 2026-04-19: 1Technical Details · 2026-08-02: 1Technical Details · 2026-08-04: 103-0503-0703-0903-1504-0704-1004-1704-3008-0208-0609-06
Signal classification4 categories
Active Exploitation
2972.5%
General
512.5%
Patch
410.0%
Disclosure
25.0%
Referenced assets35 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-052
Active Exploitation1Disclosure1
2026-03-0611
Active Exploitation9General1Patch1
2026-03-074
Active Exploitation3Disclosure1
2026-03-081
Active Exploitation1
2026-03-091
Active Exploitation1
2026-03-121
Active Exploitation1
2026-03-152
Active Exploitation1Patch1
2026-03-171
Active Exploitation1
2026-04-071
Active Exploitation1
2026-04-091
Active Exploitation1
2026-04-102
Active Exploitation2
2026-04-151
General1
2026-04-171
Active Exploitation1
2026-04-191
Active Exploitation1
2026-04-301
Active Exploitation1
2026-07-312
Active Exploitation1General1
2026-08-021
Active Exploitation1
2026-08-044
General2Patch2
2026-08-061
Active Exploitation1
2026-09-061
Active Exploitation1
Full discourse20 posts
  • Claroty@Claroty
    Patch

    📰 "CVE-2021-22681 was disclosed in February 2021, when the vendor announced mitigations and credited @Claroty for reporting it. @Claroty said at the time that it had reported the issue to Rockwell in 2019." | via @SecurityWeek https://hubs.li/Q046NyLl0 https://t.co/VgZ57kvzZ2

    Post summary

    The tweet announces the CVE‑2021‑22681 disclosure and that the vendor released mitigations, with no mention of PoC, exploit code, or active attacks.

    010201114
    4.2K followersView on X
  • Cyber_OSINT@Cyber_O51NT
    Active Exploitation

    CyberAv3ngers, IRGC-CEC-aligned, evolved from defacing water utilities to deploying IOCONTROL and exploiting CVE-2021-22681 to disrupt U.S. water, energy, and government sectors, with 60+ affiliated groups and urgent mitigations. https://www.tenable.com/blog/what-to-know-about-cyberav3ngers-the-irgc-linked-group-targeting-critical-infrastructure

    Post summary

    CyberAv3ngers are reportedly exploiting CVE-2021-22681 to disrupt U.S. water, energy, and government sectors, prompting urgent mitigations, which suggests active exploitation in the wild.

    050961.2K
    22.3K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Iranian 🇮🇷 state group CyberAv3ngers escalates from PLC defacement to deploying custom ICS malware and exploiting unpatchable Rockwell CVE-2021-22681 across US 🇺🇸 critical infrastructure. Six-agency advisory confirms operational disruption and financial losses. Technical evolution shows deliberate capability escalation: • Phase 1-2 (2020-2024): Default credential exploitation on 75+ Unitronics PLCs • Phase 3 (2024): IOCONTROL malware targeting Linux IoT/OT devices via MQTT over TLS (port 8883) • Phase 4 (2026): Active exploitation of CVE-2021-22681 (CVSS 9.8) authentication bypass in Rockwell Logix controllers Key DFIR artifacts: • Network traffic on ports 44818, 2222, 102, 22, 502 from overseas VPS providers • MQTT over TLS and DNS-over-HTTPS from OT segments • Unauthorized Studio 5000 Logix Designer connections to PLCs • Modified PLC project files and manipulated HMI/SCADA displays Critical impact factors: • No vendor patch available for CVE-2021-22681 - only defense-in-depth mitigations • Techniques proliferated to 60+ affiliated groups creating "swarm effect" • Confirmed targeting: water/wastewater, energy, government sectors Immediate action: Disconnect internet-facing PLCs, set physical mode switches to "Run", implement secure gateways with MFA. Full IOC list in CISA AA26-097A. #DFIR_Radar

    Post summary

    Iranian State Group CyberAv3ngers actively exploited the unpatched Rockwell CVE-2021-22681, causing operational disruptions in critical infrastructure, and the advisory calls for immediate mitigations.

    10013163
    1.2K followersView on X
  • Ahmed Nawaz Khalid@hushed_ahmie
    Active Exploitation

    🚨 BREAKING: CISA just added two CRITICAL CVSS 9.8 flaws to its Known Exploited Vulnerabilities (KEV) catalog! 🔥 Hikvision products: CVE-2017-7921 (Improper Authentication) → privilege escalation + sensitive data exposure 📹💥 Rockwell Automation (Logix controllers): CVE-2021-22681 (Insufficient Protected Credentials) → attackers can bypass auth, alter configs/code ⚙️🛑 Active exploitation in the wild! 😱 Federal agencies: patch by March 26, 2026! Patch NOW if you're using these! 🔧

    Post summary

    CISA has classified two critical CVEs (CVE‑2017‑7921 and CVE‑2021‑22681) as known exploited vulnerabilities with active wild attacks, urging immediate patching.

    1004079
    50 followersView on X
  • EdgeDetectOps@EdgeDetectOps
    Active Exploitation

    🚨 CVE-2021-22681: One master key compromises thousands of Rockwell factory controllers worldwide. Hackers found where it was hidden — and they're already using it. https://t.co/kHSbzUth3Y

    Post summary

    The tweet reports that attackers have discovered how to exploit the master key flaw in Rockwell factory controllers and are actively using it against thousands of devices worldwide.

    1102070
    14 followersView on X
  • DarkInvader@DarkInvaderIO
    Active Exploitation

    Minnesota water systems hit by coordinated Iranian-linked PLC attack. 30+ utilities targeted. Braham offline, Plymouth lost comms, others switched to manual ops. CVE-2021-22681 (Rockwell, no patch). Read: https://buff.ly/1LtTpC1 https://t.co/KPbV9IbfyZ

    Post summary

    An Iranian‑linked PLC attack targeted more than 30 Minnesota water utilities using CVE‑2021‑22681; the vendor has not released a patch, leaving systems exposed.

    0003096
    117 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CyberAv3ngers-linked actors knocked 30+ Minnesota water utilities offline by locking operators out of internet-exposed PLCs, and CISA is now urging immediate disconnection amid a confirmed surge in WWS sector targeting. - CVE-2021-22681 (CVSS 9.8) in Rockwell Automation controllers has been actively exploited by Iranian-affiliated actors since March 2026 with no patch available. CISA added it to KEV. Compensating controls are the only option: network isolation, IP allowlisting, and VPN-gated remote access. Rockwell published a separate notice on recovering a MicroLogix 1400 when the password has been changed by an attacker. - The attack technique is blunt but effective: remote access to internet-facing PLCs, password change, IP address change, operators locked out. No malware, no zero-day exploit chain. Just default or weak credentials on hardware that should never have been internet-exposed. Result: Braham's water plant went fully offline; boil water notices issued across multiple cities. - CISA's July 2026 advisory update expands scope beyond Rockwell to Schneider Electric and Siemens devices, and documents a new behavior: attackers are now exfiltrating PLC project files. Stealing engineering logic is pre-positioning for a more destructive follow-on attack, not just disruption. - Cellular modems installed by vendors or integrators and never documented represent a blind spot CISA explicitly flags. #DFIR_Radar

    Post summary

    The post reports active exploitation of CVE‑2021‑22681 in Rockwell PLCs by Iranian‑affiliated actors, notes no patch and recommends compensating controls like network isolation.

    10011385
    1.8K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(3/5追加) 🛡️No.1533 CVE-2017-7921 Hikvision Multiple Products Improper Authentication Vulnerability ============= CVSSスコア: 9.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:不適切な認証 (CWE-287 / CISA-ADP) 深刻度:緊急🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、ローカル上で特権昇格を行う恐れがあります。また脆弱性の悪用により、機密情報にアクセスされる可能性があります。 https://www.hikvision.com/us-en/support/document-center/special-notices/privilege-escalating-vulnerability-in-certain-hikvision-ip-cameras/ 🛡️No.1534 CVE-2021-22681 Rockwell Multiple Products Insufficient Protected Credentials Vulnerability ============= CVSSスコア: 9.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 種別:認証情報の不十分な保護 (CWE-522 / CISA-ADP) 深刻度:緊急🔥 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、Studio 5000 Logix Designerソフトウェアにおいて、キーが発見される恐れがあります。このキーは、LogixコントローラがRockwell Automationの設計ソフトウェアと通信していることを確認するために使用されます。この脆弱性が悪用されると、不正なアプリケーションがLogixコントローラに接続できるようになる可能性があります。この脆弱性を悪用するには、不正なユーザーがコントローラへのネットワークアクセスが必要になります。 https://support.rockwellautomation.com/app/answers/answer_view/a_id/1130301/~/cve-2021-22681%3A-authentication-bypass-vulnerability-found-in-logix-controllers https://www.cisa.gov/news-events/ics-advisories/icsa-21-056-03 🛡️No.1535 CVE-2021-30952 Apple Multiple Products Integer Overflow or Wraparound Vulnerability ============= CVSSスコア: 8.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:整数オーバーフローまたはラップアラウンド (CWE-190 / CISA-ADP) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、特別に細工されたWebコンテンツを介して、任意のコードを実行される恐れがあります。 https://support.apple.com/en-us/HT212975 https://support.apple.com/en-us/HT212976 https://support.apple.com/en-us/HT212978 https://support.apple.com/en-us/HT212980 https://support.apple.com/en-us/HT212982 🛡️No.1536 CVE-2023-41974 Apple iOS and iPadOS Use-After-Free Vulnerability ============= CVSSスコア: 7.8 (Base) / CISA-ADP CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:解放済みメモリの使用 (CWE-416 / CISA-ADP) 深刻度:重要 ---------------------- 悪用時影響: アプリを介して、カーネル権限で任意のコードを実行される恐れがあります。 https://support.apple.com/en-us/HT213938 https://support.apple.com/kb/HT213938 🛡️No.1537 CVE-2023-43000 Apple Multiple products Use-After-Free Vulnerability ============= CVSSスコア: 8.8 (Base) / CISA-ADP CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 種別:解放済みメモリの使用 (CWE-416 / CISA-ADP) 深刻度:重要 ---------------------- 悪用時影響: 事前認証されていない攻撃者により、特別に細工されたWebコンテンツを介して、メモリ破損が発生する恐れがあります。 https://support.apple.com/en-us/120324 https://support.apple.com/en-us/120331 https://support.apple.com/en-us/120338 CISA Adds Five Known Exploited Vulnerabilities to Catalog | CISA https://www.cisa.gov/news-events/alerts/2026/03/05/cisa-adds-five-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA confirms that five CVEs are being actively exploited in the wild, and vendor links indicate patches or workarounds are available. No PoC or exploit code is shared.

    010203.5K
    42.6K followersView on X
  • EdgeDetectOps@EdgeDetectOps
    Disclosure

    🚨 CRITICAL: CVE-2021-22681 exposes hardcoded authentication keys in Rockwell Studio 5000 Logix Designer. Attackers can extract these keys to impersonate legitimate design software and connect to industrial controllers.

    Post summary

    The tweet announces CVE-2021-22681, describing how hardcoded authentication keys in Rockwell Studio 5000 Logix Designer can be extracted to impersonate legitimate design software and target industrial controllers, with no mention of PoC, exploit code, or patches.

    1001058
    14 followersView on X
  • ShiftSix Security@Shift6Security
    General

    If you run water infrastructure: 1. Scan your public IPs for ports 44818, 502, 102, 80 2. Ask your cellular provider if field modems have public IPs 3. Check for CVE-2021-22681 on any Logix controller We run free OT exposure assessments — 60+ protocols: https://shiftsixsecurity.com/get-started

    Post summary

    The text offers scanning guidance for water‑infrastructure OT systems and lists CVE-2021-22681, but provides no PoC, exploit tool, active exploitation claim, patch details, or technical vulnerability specifics.

    1000030
    1.8K followersView on X
  • ShiftSix Security@Shift6Security
    Patch

    Rockwell said explicitly: CVE-2021-22681 cannot be patched. The auth flaw is in the protocol architecture itself. Fixing it breaks every deployed controller and engineering station. CIP Security exists for newer hardware. MicroLogix? The only mitigation is removing exposure.

    Post summary

    Rockwell declares CVE-2021-22681 is unpatchable and the sole mitigation is to remove exposure from the network.

    1000046
    1.8K followersView on X
  • ShiftSix Security@Shift6Security
    General

    If you run water infrastructure: 1. Scan your public IPs for ports 44818, 502, 102, 80 2. Ask your cellular provider if field modems have public IPs 3. Check for CVE-2021-22681 on any Logix controller We run free OT exposure assessments — 60+ protocols: https://shiftsixsecurity.com/get-started

    Post summary

    The message prompts users to scan for specific ports and check for CVE-2021-22681 on Logix controllers but provides no further technical or exploit details.

    1000036
    1.8K followersView on X
  • ShiftSix Security@Shift6Security
    Patch

    Rockwell said explicitly: CVE-2021-22681 cannot be patched. The auth flaw is in the protocol architecture itself. Fixing it breaks every deployed controller and engineering station. CIP Security exists for newer hardware. MicroLogix? The only mitigation is removing exposure.

    Post summary

    Rockwell confirmed CVE-2021-22681 is unpatchable due to architecture constraints; mitigation is limited to removing exposure, with newer hardware offering CIP Security.

    1000028
    1.8K followersView on X
  • Jheri slavante@jherislavante
    General

    @kbopulous716 @GovTimWalz Why don't you look it up... the information is out there. e.g. one of the vulnerabilities CVE-2021-22681. CISA (Fed Govt) sent out advisory in 2021. Stop posting about things you don't know about... https://www.cisa.gov/news-events/ics-advisories/icsa-21-056-03

    Post summary

    The tweet only hints at CVE-2021-22681 and cites a CISA advisory, without offering technical details, PoC evidence, or proof of exploitation.

    1000044
    174 followersView on X
  • Liv@atolivia
    Active Exploitation

    2/4 - Mines rely on Rockwell #SCADA (ControlLogix)—CISA KEV: active exploits (CVE-2021-22681 RCE exploited in-wild; CVE-2025-14027 DoS) → digital #sabotage #risk halting production or physical damage.

    Post summary

    The tweet notes that Rockwell SCADA is listed in CISA KEV with CVE-2021-22681 actively exploited as remote code execution in the wild, and mentions an unrelated DoS CVE-2025-14027.

    10000158
    1.6K followersView on X
  • ARCHIE@archie_sham
    Active Exploitation

    ⚠️ URGENT: CISA just added 2 CRITICAL vulnerabilities to its Known Exploited list — both scoring a perfect 9.8 CVSS! 🚨 🔴 Hikvision – Improper Authentication Bug CVE-2017-7921 | CVSS: 9.8 🔴 Rockwell Automation – Credentials Vulnerability CVE-2021-22681 | CVSS: 9.8 #CyberNews

    Post summary

    CISA has placed two CVEs—CVE‑2017‑7921 and CVE‑2021‑22681—on its Known Exploited list at a CVSS score of 9.8, indicating these critical vulnerabilities are currently being leveraged in the wild.

    1000084
    225 followersView on X
  • Mr.Rabbit@01ra66it
    Active Exploitation

    [Rockwell AutomationのLogix環境に関するCVE-2021-22681が、KEV(実悪用が確認された扱い)として明記された] 設計ソフトとコントローラ間の検証に使う“鍵”が発見可能となり、第三者ツールが正規アプリになりすまして接続できる可能性が示される。結果として設定やアプリケーションコード改変に繋がり得る。 能力変化としては、OT/ICS領域でも「認証の前提(鍵/検証)を崩して正規経路を奪う」攻撃が現実の運用優先度に上がった点が重い。境界防御だけでなく、制御ネットワーク内の到達性と操作監査が必須となる。 #KEV #ICS #RockwellAutomation #CVE-2021-22681 https://www.rockwellautomation.com/es-es/trust-center/security-advisories/advisory.PN1550.html

    Post summary

    CVE‑2021‑22681 is a KEV for Rockwell Automation Logix, with confirmed exploitation that lets attackers discover a verification key and impersonate legitimate applications, potentially altering settings. The advisory does not provide a PoC, exploit code, or patch details.

    10000224
    3.4K followersView on X
  • ThreatSynop@ThreatSynop
    Active Exploitation

    🚨 Old Rockwell PLC Flaw Added to KEV After Real-World ICS Exploitation Emerges SecurityWeek reports that Rockwell’s CVE-2021-22681, an authentication-bypass flaw in Studio 5000 Logix Designer and Logix PLCs, has now been confirmed as exploited in the wild and added to CISA’s KEV catalog. This matters because a remote unauthenticated attacker can impersonate an engineering workstation to access controllers, manipulate PLC logic, and potentially disrupt physical industrial processes. 🎯 Target: Global/Industrial Control Systems #️⃣ Category: #Vulnerability #TargetedAttacks #BlueTeam 🔗 URL: https://www.securityweek.com/rockwell-vulnerability-allowing-remote-ics-hacking-exploited-in-attacks/

    Post summary

    Rockwell CVE-2021-22681, an authentication-bypass flaw, has been confirmed active in the wild and added to CISA's KEV catalog, enabling attackers to remotely hijack PLCs and threaten industrial processes.

    1000060
    258 followersView on X
  • サイバーセキュリティニュース-JP@cybersecnews_jp
    General

    CISA、5つの既知の脆弱性をカタログに追加 https://www.cisa.gov/news-events/alerts/2026/03/05/cisa-adds-five-known-exploited-vulnerabilities-catalog CVE-2017-7921 Hikvision 複数製品における不適切な認証の脆弱性 CVE-2021-22681 Rockwell 複数製品における保護された資格情報の不十分な脆弱性

    Post summary

    CISA announced that five known exploited vulnerabilities have been added to its catalog, highlighting two CVEs (Hikvision authentication flaw CVE‑2017‑7921 and Rockwell credential protection issue CVE‑2021‑22681). No PoC, exploit code, patch information, or debunking is included.

    1000037
    47 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2021-22681 - n/a - Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers - https://www.redpacketsecurity.com/cve-alert-cve-2021-22681-n-a-rockwell-automation-studio-5000-logix-designer-rslogix-5000-logix-controllers/ #OSINT #ThreatIntel #CyberSecurity #cve-2021-22681 #n-a #rockwell-automation-studio-5000-logix-designer-rslogix-5000-logix-controllers

    Post summary

    The tweet announces CVE‑2021‑22681 for Rockwell Automation products and links to a CVE alert page, but it does not include technical details, exploit code, or patch information.

    00010136
    3.5K followersView on X
CPE platform detail20 entries

20 of 20 entries

PartVendorProductVersionTarget SWTarget HW
HWrockwellautomationcompact_guardlogix_5370---
HWrockwellautomationcompact_guardlogix_5380---
HWrockwellautomationcompactlogix_1768---
HWrockwellautomationcompactlogix_1769---
HWrockwellautomationcompactlogix_5370---
HWrockwellautomationcompactlogix_5380---
HWrockwellautomationcompactlogix_5480---
HWrockwellautomationcontrollogix_5550---
HWrockwellautomationcontrollogix_5560---
HWrockwellautomationcontrollogix_5570---
HWrockwellautomationcontrollogix_5580---
HWrockwellautomationdrivelogix_1794-l34---
HWrockwellautomationdrivelogix_5560---
HWrockwellautomationdrivelogix_5730---
Approckwellautomationfactorytalk_services_platform---
HWrockwellautomationguardlogix_5570---
HWrockwellautomationguardlogix_5580---
Approckwellautomationrslogix_5000---
HWrockwellautomationsoftlogix_5800---
Approckwellautomationstudio_5000_logix_designer---

Explore more