Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2021-22681
n/a Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers — Rockwell Multiple Products
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U H H H 9.8 .6363 99.2 YES
AFFECTED
Product Versions Fixed
Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers RSLogix 5000 Versions 16 through 20 – —
TIMELINE
Jan 5 Reserved by icscert
Mar 3 Published (CNA: icscert)
Mar 5 Added to CISA KEV, remediation due 2026-03-26
Description
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800. Rockwell Automation Studio 5000 Logix Designer Versions 21 and later and RSLogix 5000: Versions 16 through 20 are vulnerable because an unauthenticated attacker could bypass this verification mechanism and authenticate with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| January 5, 2021 | Reserved | Reserved by icscert |
| March 3, 2021 | Published | Published (CNA: icscert) |
| March 5, 2026 | KEV ADDED | Added to CISA KEV, remediation due 2026-03-26 |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| n/a | Rockwell Automation Studio 5000 Logix Designer, RSLogix 5000, Logix Controllers | — | RSLogix 5000 Versions 16 through 20 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2021-22681 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.