Home / Vulnerabilities / CVE-2021-22681
CRITICAL SEVERITY
CVE-2021-22681Rockwell · Multiple Products

Rockwell Multiple Products Insufficient Protected Credentials Vulnerability

Technical Severity

CVSS v3.1 Metrics

CRITICAL
9.8 / 10
Minimal Risk Critical
Vector Specification
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Likelihood

EPSS Prediction

12.90 %
Predictive Probability
Percentile Rank
94.0 th

Documented as more likely to be exploited than 94.0% of known CVEs.

Detection Date

Mar 05, 2026

Remediation Due

Mar 26, 2026

CISA Catalog Active

Threat Analysis

Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to verify Logix controllers are communicating with Rockwell Automation design software. If successfully exploited, this vulnerability could allow an unauthorized application to connect with Logix controllers. To leverage this vulnerability, an unauthorized user would require network access to the controller.

Remediation Directive

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

External Intelligence