logo

Team82 Discovers Critical Authentication Bypass in Rockwell Software

ID: 0cfd8dba-8e80-57cd-a252-8dfcdda87d3c

STIX ID: report--0cfd8dba-8e80-57cd-a252-8dfcdda87d3c

Feed Name: Claroty Team82

Threat Score
80/100

Date Published: 2023-09-20

Date Updated: 2026-04-17

Author: Sharon Brizinov

...
...

Claroty (with independent discoverers) reported a critical vulnerability (CVE-2021-22681, CVSS 10.0) in Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000 and many Logix controllers that can allow an attacker to extract a secret cryptographic key and remotely authenticate to PLCs, enabling upload/download of logic, firmware changes, or data theft. The advisory lists affected product families and versions, recommends mitigations such as deploying CIP Security, network segmentation, secure remote access, and controller monitoring features, and provides guidance for detecting unauthorized configuration changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.