Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Rockwell Vulnerability Allowing Remote ICS Hacking Exploited in Attacks
    Cybersecurity

    Rockwell Vulnerability Allowing Remote ICS Hacking Exploited in Attacks

    adminBy adminMarch 8, 2026No Comments2 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Rockwell Automation vulnerabilities
    Share
    Facebook Twitter LinkedIn Pinterest Email

    An old vulnerability affecting industrial control system (ICS) products from Rockwell Automation has been exploited in attacks, according to the vendor and the cybersecurity agency CISA.

    CISA added the flaw, tracked as CVE-2021-22681, to its Known Exploited Vulnerabilities (KEV) catalog on Thursday, instructing federal agencies to address it by March 26. 

    The security hole affects the Studio 5000 Logix Designer software and several Logix programmable logic controllers (PLCs), including CompactLogix, ControlLogix, DriveLogix, FlexLogix, GuardLogix, and SoftLogix devices.

    CVE-2021-22681 was disclosed in February 2021, when the vendor announced mitigations and credited Soonchunhyang University in South Korea, Kaspersky, and Claroty for reporting it. Claroty said at the time that it had reported the issue to Rockwell in 2019.

    The vulnerability, related to an insufficiently protected cryptographic key, could allow a remote, unauthenticated attacker to bypass verification and connect to a targeted controller by mimicking an engineering workstation.

    In a real-world industrial environment, the vulnerability could allow remote attackers to manipulate PLC logic and disrupt manufacturing processes, or even cause physical damage to equipment.  

    Advertisement. Scroll to continue reading.

    Rockwell updated its initial advisory on Thursday to mention in-the-wild exploitation of CVE-2021-22681, but the company has not shared any information about the attacks.

    SecurityWeek has reached out to Rockwell for comment and will update this article if the company responds.

    A Shodan search currently shows nearly 6,000 internet-exposed Rockwell devices, but it’s unclear how many may be affected by CVE-2021-22681.

    It’s worth noting that Rockwell issued a security notice in 2024, urging customers to ensure their ICS devices are not connected to the internet. One of the vulnerabilities highlighted in that alert was CVE-2021-22681, which indicates that the vendor did not rule out malicious exploitation. 

    In 2023, Rockwell and CISA warned that an unnamed APT had developed an exploit for a different Rockwell controller vulnerability (CVE-2023-3595), which could be exploited to cause disruption or destruction, but there had been no evidence of actual attacks. 

    Currently, CVE-2021-22681 is the only Rockwell product vulnerability in CISA’s KEV catalog. 

    Related: 3 Threat Groups Started Targeting ICS/OT in 2025: Dragos

    Related: Honeywell, Researcher Clash Over Impact of Building Controller Vulnerability

    Related: Critical Flaws Exposed Gardyn Smart Gardens to Remote Hacking

    Allowing attacks Exploited hacking ICS Remote Rockwell vulnerability
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleWindows 11’s new feature will make it really easy to toggle dark mode
    Next Article AI agents: Powering Europe’s most ambitious startups
    admin
    • Website

    Related Posts

    Critical vulnerability in Cisco Secure Workload rated at maximum severity

    May 22, 2026

    Encryption Consulting launches CertSecure Manager v3.3 with zero-touch certificate renewals

    May 20, 2026

    GitHub confirms breach of 3,800 repos via malicious VSCode extension

    May 20, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Using AI to Support and Defend Your Brand

    June 10, 2026

    6 Ways to Automate International Marketing with Agent A

    June 10, 2026

    What Is Network Experience Management? A Guide for IT Teams

    June 10, 2026

    Google Search Sends 23% Of Queries To The Open Web

    June 10, 2026
    Categories
    • Blogging (92)
    • Cybersecurity (1,955)
    • Privacy & Online Earning (249)
    • SEO & Digital Marketing (1,438)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (345)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Using AI to Support and Defend Your Brand

    June 10, 2026

    6 Ways to Automate International Marketing with Agent A

    June 10, 2026

    What Is Network Experience Management? A Guide for IT Teams

    June 10, 2026
    Most Popular
    • Using AI to Support and Defend Your Brand
    • 6 Ways to Automate International Marketing with Agent A
    • What Is Network Experience Management? A Guide for IT Teams
    • Google Search Sends 23% Of Queries To The Open Web
    • Residential proxies are hiding in plain sight inside enterprise networks
    • How to Advertise on Facebook in 8 Steps: The Visual Guide
    • How Taegan Goddard Turned Political Wire’s 4 to 5 Million Monthly Visitors Into a Subscription Opportunity
    • How to make prompt tracking much more accurate
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.