IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix

HIGH
CVSS 7.5
Date 2026-09-01T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2021-42260 7.5 high
A potential denial of service vulnerability exists in the affected products and can be triggered via corrupt crafted data. This could result in a major nonrecoverable fault (MNRF). A program download is required to recover safety controllers. For non-safety controllers, a stage 2 reset is required to recover.

// Affected Products (3)

Vendor Product Asset Type Purdue Level Firmware
Rockwell Automation Unknown plc
L1
v.32.011
Rockwell Automation Unknown plc
L1
35.013
Rockwell Automation Unknown plc
L1
v.32.011

// Remediations (5)

Patch: Rockwell Automation recommends users update to firmware version 35.014 and later.
Rockwell Automation recommends users update to firmware version 35.014 and later.
Mitigation: Customers using the affected software who are not able to upgrade to one of the corrected versions s
Customers using the affected software who are not able to upgrade to one of the corrected versions should use Rockwell Automation's security best practices.
Patch: Rockwell Automation recommends users update to firmware version 36.013 and later.
Rockwell Automation recommends users update to firmware version 36.013 and later.
Patch: Rockwell Automation recommends users update to firmware version 37.011 and later.
Rockwell Automation recommends users update to firmware version 37.011 and later.
Patch: Rockwell Automation recommends users update to firmware version 34.015 and later.
Rockwell Automation recommends users update to firmware version 34.015 and later.

// References