Security/ ics security · rockwell automation · cisa advisory · denial of service

CISA Reissues Rockwell Logix Advisory Over 2021 DoS Bug

A 2021 flaw that can crash Rockwell's ControlLogix and GuardLogix controllers has a fresh advisory, and safety models need a full program reload to recover.

CISA has republished a Rockwell Automation advisory warning that several of its Logix industrial controllers can be frozen with nothing more than corrupt network data.

The affected lineup includes ControlLogix 5580, GuardLogix 5580, CompactLogix 5380 and 5480, and Compact GuardLogix 5380 controllers running firmware older than versions 34.015, 35.014, 36.013, or 37.011, depending on the branch. The flaw, tracked as CVE-2021-42260, is an infinite loop that can be triggered by specially crafted data, pushing the device into what Rockwell calls a major nonrecoverable fault. CISA rates it 7.5 out of 10 under CVSS 3.1 and 8.7 under the newer CVSS 4.0 scale, both in the high-severity range. Rockwell's fix is a firmware update to the patched versions; anyone who cannot update right away is pointed to Rockwell's standard security best practices.

The recovery process is the real headache. A safety-rated controller that hits this fault needs a full program download to come back online, not a quick reboot. Non-safety controllers get off easier with a stage 2 reset, but either way, that is downtime on a factory floor, not a browser refresh. These controllers run in critical manufacturing plants worldwide, and a remote attacker who can reach the network needs no credentials or user interaction to force a hard stop.

Worth noting: CVE-2021-42260 is not new. It was first disclosed in 2021, and this advisory is CISA's republication of Rockwell's existing guidance rather than a fresh discovery, with no public exploitation reported. That gap between disclosure and republication says less about urgency and more about how much slower industrial patch cycles move compared to ordinary IT.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →