vulnerability

Rockwell Automation Compact GuardLogix 5380: CVE-2021-22681 Authentication Bypass

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Feb 25, 2021
Added
Mar 16, 2026
Modified
Mar 16, 2026

Description

The Rockwell Automation Compact GuardLogix 5380 controller uses a hardcoded cryptographic key for communication verification. Unauthenticated remote attackers can extract this key to bypass authentication, allowing them to mimic an engineering workstation and manipulate controller logic or configurations.

Solution

rockwell-compact-guardlogix-5380-cve-2021-22681-solution
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.