Remote Code Execution Vulnerability in Rockwell Automation MicroLogix 1400
CVE-2021-22659

8.6HIGH

Key Information:

Vendor
CVE Published:
25 March 2021

What is CVE-2021-22659?

Rockwell Automation's MicroLogix 1400, particularly Version 21.6 and earlier, is susceptible to a vulnerability that enables remote unauthenticated attackers to exploit specially crafted Modbus packets. This exploitation can lead to unauthorized retrieval and modification of arbitrary values within the device's register. A successful attack may result in a buffer overflow, triggering a denial-of-service state where the FAULT LED signals an issue and communication may cease altogether. Users must actively clear the fault to restore normal operations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Rockwell Automation MicroLogix 1400 MicroLogix 1400, All series Version 21.6 and below

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.