Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Evidence dossier
CVE-2021-22681
CVE-2021-22681
gen-56ccdaf9Normalized restatement
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.
- State
- PUBLISHED
- Published
- Mar 3, 2021
- Updated
- Mar 6, 2026
- Evidence coverage
- 72%
2026-07-18 · v2026.06.15 · percentile 97.7%
Distinct CVSS assessments remain side by side; none are averaged.
Source comparison
Who said what
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.
Rockwell Multiple Products Insufficient Protected Credentials Vulnerability
Probability 0.254550000000; percentile 0.977170000000
Applicability
Cited product scope
[{"status": "affected", "version": "RSLogix 5000 Versions 16 through 20"}, {"status": "affected", "version": "Studio 5000 Logix Designer: Versions 21 and later"}, {"status": "affected", "version": "CompactLogix 1768, 1769, 5370, 5380, 5480"}, {"status": "affected", "version": "ControlLogix 5550, 5560, 5570, 5580"}, {"status": "affected", "version": "DriveLogix 5560, 5730, 1794-L34"}, {"status": "affected", "version": "Compact GuardLogix 5370, 5380"}, {"status": "affected", "version": "GuardLogix 5570, 5580"}, {"status": "affected", "version": "SoftLogix 5800"}]unknowncpe:2.3:a:rockwellautomation:factorytalk_services_platform:*:*:*:*:*:*:*:*; start including 2.10supportedcpe:2.3:a:rockwellautomation:rslogix_5000:*:*:*:*:*:*:*:*; start including 16; end including 20supportedcpe:2.3:a:rockwellautomation:studio_5000_logix_designer:*:*:*:*:*:*:*:*; start including 21.0supportedcpe:2.3:h:rockwellautomation:compact_guardlogix_5370:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:rockwellautomation:compact_guardlogix_5380:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:rockwellautomation:compactlogix_1768:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:rockwellautomation:compactlogix_1769:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:rockwellautomation:compactlogix_5370:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:rockwellautomation:compactlogix_5380:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:rockwellautomation:compactlogix_5480:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:rockwellautomation:controllogix_5550:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:rockwellautomation:controllogix_5560:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:rockwellautomation:controllogix_5570:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:rockwellautomation:controllogix_5580:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:rockwellautomation:drivelogix_1794-l34:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:rockwellautomation:drivelogix_5560:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:rockwellautomation:drivelogix_5730:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:rockwellautomation:guardlogix_5570:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:rockwellautomation:guardlogix_5580:-:*:*:*:*:*:*:*constrainedcpe:2.3:h:rockwellautomation:softlogix_5800:-:*:*:*:*:*:*:*constrainedAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:P/I:P/A:PCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLimitations and unknowns
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; unresolved scope remains unknown.
- NVD-carried upstream facts remain derivative and are not independent corroboration.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Factor D is unknown in Public Core because no accepted canonical mapping-obligation ledger is present.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.