CISA KEV · catalog date Mar 5, 2026 · first observed Jul 19, 2026
Evidence dossier
CVE-2021-22681
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with…
Exploited in the wild (CISA KEV since Mar 5, 2026). NVD reports CVSS 3.1 9.8. EPSS estimates 63.6% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.
- State
- PUBLISHED
- Published
- Mar 3, 2021
- Updated
- Mar 6, 2026
- Evidence coverage
- 96%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAicscertOriginal evidence ↗
Record text: Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.
Inspect raw assertion
- Field
container- Value
- Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Rockwell Multiple Products Insufficient Protected Credentials Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Rockwell Multiple Products Insufficient Protected Credentials Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 63.63% probability · 99.15th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.636300000000; percentile 0.991530000000
FIRST EPSS · score date Aug 27, 2026 · 99.2th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.
Inspect raw assertion
- Field
container- Value
- Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.
Rockwell Multiple Products Insufficient Protected Credentials Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Rockwell Multiple Products Insufficient Protected Credentials Vulnerability
63.63% probability · 99.15th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.636300000000; percentile 0.991530000000
Applicability
Cited product scope
Grouped from 2 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
21 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "RSLogix 5000 Versions 16 through 20"}, {"status": "affected", "version": "Studio 5000 Logix Designer: Versions 21 and later"}, {"status": "affected", "version": "CompactLogix 1768, 1769, 5370, 5380, 5480"}, {"status": "affected", "version": "ControlLogix 5550, 5560, 5570, 5580"}, {"status": "affected", "version": "DriveLogix 5560, 5730, 1794-L34"}, {"status": "affected", "version": "Compact GuardLogix 5370, 5380"}, {"status": "affected", "version": "GuardLogix 5570, 5580"}, {"status": "affected", "version": "SoftLogix 5800"}]product-d3b679faf0205fe015339cf0972b0ef483bf809cc8b2d9a13be8ca034bc028b1Linked exactInspect raw assertion
cpe:2.3:h:rockwellautomation:compact_guardlogix_5370:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6f951670-af4d-4429-8bc1-79bdef83b2c3
product-60a3deefacd65c114f2895f76885a31dd4254add4845c2d5bfcf183f3e30e337Linked exactInspect raw assertion
cpe:2.3:h:rockwellautomation:compact_guardlogix_5380:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
62414e65-73c7-4172-b7bf-f40a66afbb90
product-9d20a854804c3bad089e875c2db7e44f3338dacbd861b311d22da939801d6db1Linked exactInspect raw assertion
cpe:2.3:h:rockwellautomation:compactlogix_1768:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2e5f100a-c8a3-49f2-b1d2-411432472b6b
product-768c9343b1e7ba6f6ea6cb77d91c7a63ceec7f93d2f558824bc84f0819d5bfe4Linked exactInspect raw assertion
cpe:2.3:h:rockwellautomation:compactlogix_1769:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f8a690bc-4d7c-4b83-a9f6-f860445028a2
product-c2952463999209b06cd494a07a4087aef7e14be3ad5376aa3a44d1589f14a8f0Linked exactInspect raw assertion
cpe:2.3:h:rockwellautomation:compactlogix_5370:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e12adae3-97b1-48bc-be69-ed75667c1886
product-c6b110ef248c09338971d629decac3ebdaded35a4e994fd02a792d3b6e220d33Linked exactInspect raw assertion
cpe:2.3:h:rockwellautomation:compactlogix_5380:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
edd040ed-b44c-47d0-b4d4-729c378c4f68
product-49b3e7a9d1322e677f6885c6f63da6cf394a43fc678e82cce7e37acdd928c073Linked exactInspect raw assertion
cpe:2.3:h:rockwellautomation:compactlogix_5480:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
80f4f5be-07df-402a-bf98-34fba6a11968
product-25c418bb04334dbdc401ec0d53ce6dabdc44a17a9c48bfa11f9357d61ad37c90Linked exactInspect raw assertion
cpe:2.3:h:rockwellautomation:controllogix_5550:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
13ee2216-f25f-44ab-a167-4eea153c8f8d
product-e0e524cf0f3e66d54464b74b867796252f79fc6ac6c44fa88540ce2d7c070affLinked exactInspect raw assertion
cpe:2.3:h:rockwellautomation:controllogix_5560:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ea25ff8d-51c5-4928-9b90-e4bd1476f50b
product-2461e34f374557ca328bf422deaf6946cc1d795cf128c09c03d9d9dc6fc9957aLinked exactInspect raw assertion
cpe:2.3:h:rockwellautomation:controllogix_5570:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
482e2cd6-d484-486c-92f4-18432d107e30
product-c28d5ef494ee8b002301de5b4653a4d1f2a0e80d26144cd115437bc23a73c38eLinked exactInspect raw assertion
cpe:2.3:h:rockwellautomation:controllogix_5580:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
51bb883b-b863-4d57-b1c0-fc7b3ebd1ea0
product-e60e15e0f0228950df923a1e4d3e1449efaec7824fa7ba623ca39b0927e17d5aLinked exactInspect raw assertion
cpe:2.3:h:rockwellautomation:drivelogix_1794-l34:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4a75a0fd-c337-4264-b1e4-96701851d6fa
product-00a0da33b2827c7d5cdda676abf60d8a6aa96a606b7405bea22ed28d10e54e4bLinked exactInspect raw assertion
cpe:2.3:h:rockwellautomation:drivelogix_5560:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
dfdaaa77-6964-44fc-9ffb-ecdf71665965
product-ffaab5342d1994a911749837740b25d5fe341e424d82d0989f706c6a923f6411Linked exactInspect raw assertion
cpe:2.3:h:rockwellautomation:drivelogix_5730:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
03e185c3-17ca-4e3f-863b-9f906c5c59ea
product-fa5802da7776c2f7c6e860b7ca743662157d24cfd2aef6a1411d988189441e1fLinked exactInspect raw assertion
cpe:2.3:a:rockwellautomation:factorytalk_services_platform:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 2.10
- Match ID
6755fcf6-4a0c-478a-aeff-54e35c45149d
product-e29513ca7788137d5de2aab08d82b8bc259e541fe7da44a9d50bd2a388344359Linked exactInspect raw assertion
cpe:2.3:h:rockwellautomation:guardlogix_5570:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
321ae938-192a-4342-8608-adc81f0b6582
product-d8f3c619c4b390d5c9a41a8a5ffe3afe552c905e1b6ed0d8d192e88bad9ed3a6Linked exactInspect raw assertion
cpe:2.3:h:rockwellautomation:guardlogix_5580:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
006b7683-9fdf-4748-ba28-2ea22613e092
product-33da92da2f265daa0060d56a6a1d076177460fab320186b50feb0bff16b595b1Linked exactInspect raw assertion
cpe:2.3:a:rockwellautomation:rslogix_5000:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 16; through including 20
- Match ID
04c30129-3f03-4486-b181-ebde29751372
product-e64a3aca777150ceff073e57c480258f742de5e9eaa35b6ab262013ba8c989a2Linked exactInspect raw assertion
cpe:2.3:h:rockwellautomation:softlogix_5800:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bdab7b6d-ccac-460b-8a88-3397a2397078
product-23735fff1dfcd264ccd5aca5ece35c54ab9b99fb48f7e2dd72acedf5729c0042Linked exactInspect raw assertion
cpe:2.3:a:rockwellautomation:studio_5000_logix_designer:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 21.0
- Match ID
9c840463-a11f-43a0-aa45-1ac810713ab6
Affected-product evidence
Accepted scope and product mapping
3 canonical links · 1 source-reported links
vendor-c4d6775ce29222cdb0b7d7810ba87d2e4be2e981e2c873e80c97672aafc978dc · product-23735fff1dfcd264ccd5aca5ece35c54ab9b99fb48f7e2dd72acedf5729c0042
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
98844ac8-9b09-44af-9ba2-347a2132854dvendor-c4d6775ce29222cdb0b7d7810ba87d2e4be2e981e2c873e80c97672aafc978dc · product-33da92da2f265daa0060d56a6a1d076177460fab320186b50feb0bff16b595b1
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
19c8be6d-5d0f-4d6a-8df9-55659ad8eb75vendor-c4d6775ce29222cdb0b7d7810ba87d2e4be2e981e2c873e80c97672aafc978dc · product-fa5802da7776c2f7c6e860b7ca743662157d24cfd2aef6a1411d988189441e1f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0ea1b414-57fb-4f2c-bef8-8a8992c02a70Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5b21bb2a-eebe-4d0d-aa7f-4b81cfde87a1Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:P/I:P/A:PCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.