Rockwell’s latest patch set matters, but the operational problem is the older, already-exploited trust path that is still sitting in deployed OT gear. The company confirmed in-the-wild abuse of CVE-2021-22681, even as its new advisories for Logix, CompactLogix, ControlLogix, Flex I/O, RSLinx, and FactoryTalk have not yet been seen targeted.
The new fixes cover DoS bugs in controllers, authentication-bypass and password-change issues in FactoryTalk Historian Site Edition and Flex I/O dual-port Ethernet/IP adapters, and an improper API authorization flaw in FactoryTalk Analytics PavilionX. For plant and critical-infrastructure teams, the sharper risk is still legacy engineering and controller assets that trust device identity or session state and may be exposed through a path attackers already know works.
Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP | CISA
Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP Summary Successful exploitation of this vulnerability could cause a denial-of-service condition that may result in a major nonrecoverable fault (MNRF).
Rockwell Automation RSLinx Summary Successful exploitation of this vulnerability can lead to a denial of service, where the application will become unresponsive and will not recover on its own.