#VU51000 Insufficiently protected credentials in RSLogix 5000 and Studio 5000 Logix Designer - CVE-2021-22681
Published: March 1, 2021 / Updated: March 2, 2021
RSLogix 5000
Studio 5000 Logix Designer
Rockwell Automation
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected product uses a key to verify Logix controllers are communicating with the affected Rockwell Automation products. A remote attacker can bypass this verification mechanism and authenticate with Logix controllers.
This vulnerability affects the following Rockwell Logix Controllers:
- CompactLogix 1768
- CompactLogix 1769
- CompactLogix 5370
- CompactLogix 5380
- CompactLogix 5480
- ControlLogix 5550
- ControlLogix 5560
- ControlLogix 5570
- ControlLogix 5580
- DriveLogix 5560
- DriveLogix 5730
- DriveLogix 1794-L34
- Compact GuardLogix 5370
- Compact GuardLogix 5380
- GuardLogix 5570
- GuardLogix 5580
- SoftLogix 5800