Rockwell Logix Controllers DoS Flaw Patched
CISA advisory details a denial-of-service vulnerability in Rockwell Automation ControlLogix/CompactLogix/GuardLogix firmware requiring update or manual recovery.
CISA published an ICS advisory covering a denial-of-service vulnerability (CVE-2021-42260) affecting multiple Rockwell Automation Logix controller product lines, including ControlLogix 5580, GuardLogix 5580, CompactLogix 5380, Compact GuardLogix 5380, and CompactLogix 5480. The flaw stems from an infinite loop condition (CWE-835) that can be triggered by corrupt or crafted data, resulting in a Major Nonrecoverable Fault (MNRF). Recovery requires a program download for safety controllers or a stage 2 reset for non-safety controllers, meaning exploitation would cause operational disruption requiring manual intervention to restore the device.
The affected products span multiple firmware revision branches (versions below 34.015, 35.014, 36.013, and 37.011). Rockwell Automation has released corrected firmware for each branch and reported the issue to CISA. These controllers are deployed worldwide in critical manufacturing environments. No public exploitation of this vulnerability has been reported to CISA at this time.
CISA recommends standard ICS defense-in-depth practices: minimizing network exposure of control system devices, isolating control networks behind firewalls, and using VPNs for any necessary remote access while acknowledging VPNs carry their own risk. Organizations unable to immediately apply the firmware updates should implement Rockwell's security best practices as a compensating control. Given the lack of known in-the-wild exploitation and the requirement for local/network access to send malformed data, this is a routine ICS patch advisory rather than an active threat.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-05
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free