← לוח פגיעויות

CVE-2021-22681

קריטית 9.8 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Rockwell Multiple Products Insufficient Protected Credentials Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

תיאור (מקור, אנגלית)

Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.

מדדים

CVSS 3.1
9.8 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — סבירות ניצול
51% (אחוזון 100) נכון ל-30/7/2026
CWE
CWE-522

מוצרים מושפעים

rockwellautomation: factorytalk services platform; rockwellautomation: rslogix 5000; rockwellautomation: studio 5000 logix designer; rockwellautomation: compact guardlogix 5370; rockwellautomation: compact guardlogix 5380; rockwellautomation: compactlogix 1768; rockwellautomation: compactlogix 1769; rockwellautomation: compactlogix 5370; rockwellautomation: compactlogix 5380; rockwellautomation: compactlogix 5480; rockwellautomation: controllogix 5550; rockwellautomation: controllogix 5560; rockwellautomation: controllogix 5570; rockwellautomation: controllogix 5580; rockwellautomation: drivelogix 1794-l34

קישורים