SB2021030105 - Insufficiently protected credentials in Rockwell Automation Logix Controllers



SB2021030105 - Insufficiently protected credentials in Rockwell Automation Logix Controllers

Published: March 1, 2021

Security Bulletin ID SB2021030105
Severity
High
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Insufficiently protected credentials (CVE-ID: CVE-2021-22681)

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the affected product uses a key to verify Logix controllers are communicating with the affected Rockwell Automation products. A remote attacker can bypass this verification mechanism and authenticate with Logix controllers.

This vulnerability affects the following Rockwell Logix Controllers:

  • CompactLogix 1768
  • CompactLogix 1769
  • CompactLogix 5370
  • CompactLogix 5380
  • CompactLogix 5480
  • ControlLogix 5550
  • ControlLogix 5560
  • ControlLogix 5570
  • ControlLogix 5580
  • DriveLogix 5560
  • DriveLogix 5730
  • DriveLogix 1794-L34
  • Compact GuardLogix 5370
  • Compact GuardLogix 5380
  • GuardLogix 5570
  • GuardLogix 5580
  • SoftLogix 5800

Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.