Skip to main content
Mallory
CriticalCISA KEVExploited in the wildPublic exploit

Authentication Bypass in Rockwell Automation Logix Controllers

IdentifiersCVE-2021-22681CWE-522· Insufficiently Protected Credentials

CVE-2021-22681 is a critical authentication bypass / insufficiently protected credentials issue affecting Rockwell Automation Studio 5000 Logix Designer versions 21 and later, RSLogix 5000 versions 16 through 20, and communications with multiple Logix controller families, including CompactLogix, ControlLogix, GuardLogix, DriveLogix, and SoftLogix. The vulnerable design uses a key to verify that Logix controllers are communicating with trusted Rockwell engineering software. That key can be discovered or extracted, allowing an unauthenticated attacker to bypass the verification mechanism and authenticate to affected controllers as though they were an authorized workstation or application. Rockwell and CISA reporting indicate the flaw enables unauthorized applications to establish accepted connections to controllers without valid credentials once the verification key is obtained.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can allow a remote, unauthenticated attacker with network access to an affected controller to impersonate a trusted engineering workstation, authenticate to the controller, and interact with it as an authorized application. This can enable unauthorized changes to controller configuration and/or application logic, extraction of project files, malicious interaction with PLC project files, and manipulation of data presented to HMI/SCADA systems. In operational environments, this creates risk of process disruption, loss of control integrity, operational downtime, financial loss, and potentially unsafe physical consequences depending on the controlled process.

Mitigation

If you can’t patch tonight, do this now.

Mitigate by eliminating direct public internet exposure of affected PLCs, mediating remote access through secure gateways, jump hosts, firewalls, proxies, or VPNs, and tightly restricting network reachability to controller management and engineering protocols such as TCP/44818. Segment OT networks so Logix controllers are reachable only from authorized engineering workstations, monitor for anomalous engineering traffic and unauthorized accepted connections, block unnecessary services and ports, and place controllers with physical mode switches into run mode where operationally appropriate to prevent remote modification. Review and implement Rockwell’s published guidance for CVE-2021-22681 and broader OT hardening recommendations.

Remediation

Patch, then assume compromise.

No software patch is available to fully remediate this vulnerability according to the provided Rockwell guidance. Organizations should follow Rockwell Automation guidance such as PN1550 and related hardening advisories, remove affected controllers from direct internet exposure, and apply compensating controls around controller communications. Where supported and feasible, deploy vendor-recommended protections such as CIP Security or a CIP Security proxy, restrict engineering access to trusted hosts and zones only, and review Rockwell PSIRT guidance for affected deployments.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Rockwell AutomationFactorytalk Services Platformapplication
Rockwell AutomationRslogix 5000application
Rockwell AutomationStudio 5000 Logix Designerapplication

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

ACTIVITY FEED

Recent activity

32 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence1

Every observed campaign linking this CVE to a named adversary.

Associated malware1

Malware families riding this exploit, with evidence and IOCs.

Detection signatures1

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity17

Community discussion across Reddit, Mastodon, and other social sources.