Description


CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including the workstation. To recover the controllers, a download is required which ends any process that the controller is running.

Related CPE's


o

rockwellautomation

controllogix_5580_firmware

3


o

rockwellautomation

controllogix_5580_process_firmware

3


o

rockwellautomation

guardlogix_5580_firmware

3


o

rockwellautomation

compactlogix_5380_firmware

3


o

rockwellautomation

compact_guardlogix_5380_sil_2_firmware

3


o

rockwellautomation

compact_guardlogix_5380_sil_3_firmware

3


o

rockwellautomation

compactlogix_5480_firmware

3


o

rockwellautomation

factorytalk_logix_echo_firmware

2

Weaknesses



CWE-20


NVD-CWE-noinfo

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.5 · High

Information


Source identifier

[email protected]

Vulnerability status

Analyzed

Published

2024-10-14T19:15:12.460Z

1 year ago

Last modified

2024-10-21T11:20:45.617Z

1 year ago