Rapid7

vulnerability

Rockwell Automation DriveLogix 5730: CVE-2021-22681 Authentication Bypass

Severity
10
CVSS
(AV:N/AC:L/Au:N/C:C/I:C/A:C)
Published
Feb 25, 2021
Added
Mar 16, 2026
Modified
Mar 16, 2026

Description

The Rockwell Automation DriveLogix 5730 controller uses a hardcoded cryptographic key for communication verification. Unauthenticated remote attackers can extract this key to bypass authentication, allowing them to mimic an engineering workstation and manipulate controller logic or configurations.

Solution

rockwell-drivelogix-5730-cve-2021-22681-solution
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.