Description
CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including the workstation. To recover the controllers, a download is required which ends any process that the controller is running.
Related CPE's
o
rockwellautomation
controllogix_5580_firmware
o
rockwellautomation
controllogix_5580_process_firmware
o
rockwellautomation
guardlogix_5580_firmware
o
rockwellautomation
compactlogix_5380_firmware
o
rockwellautomation
compact_guardlogix_5380_sil_2_firmware
o
rockwellautomation
compact_guardlogix_5380_sil_3_firmware
o
rockwellautomation
compactlogix_5480_firmware
o
rockwellautomation
factorytalk_logix_echo_firmware
References
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
7.5 · High
Information
Source identifier
Vulnerability status
Analyzed
Published
2024-10-14T19:15:12.460Z
1 year agoLast modified
2024-10-21T11:20:45.617Z
1 year ago