Back to all lessons
Awareness Lessons
last month

Rockwell Automation PLC Vulnerability Enables Denial-of-Service on Industrial Control Systems

A denial-of-service vulnerability (CVE-2021-42260) in multiple Rockwell Automation ControlLogix and GuardLogix product lines allows attackers to trigger a major nonrecoverable fault, effectively halting industrial operations until manual recovery steps are performed. This is particularly dangerous in operational technology (OT) environments where availability is critical to safety and production continuity. The fact that recovery requires a program download or stage 2 reset means even a brief exploitation event can result in significant downtime and potential physical-world consequences. Unpatched industrial control systems remain one of the highest-risk attack surfaces in critical infrastructure, as firmware updates are often delayed due to operational constraints.

Tactical Insight

Immediate Actions

  • Apply Rockwell Automation's recommended firmware updates to all affected ControlLogix, CompactLogix, GuardLogix, and Compact GuardLogix devices immediately.
  • Conduct an asset inventory audit to identify all affected product versions currently deployed in your environment.

Long-Term Improvements

  • Establish a formal OT/ICS patch management program with defined timelines and risk-based prioritization for firmware updates.
  • Implement strict network segmentation to isolate industrial control systems from corporate IT networks and the internet using firewalls and DMZs.
  • Develop and regularly test recovery runbooks specific to ICS faults, including program download and stage reset procedures.

Detection Measures

  • Deploy OT-aware intrusion detection systems (e.g., Claroty, Dragos, or Nozomi) to monitor for anomalous traffic targeting PLC communication protocols.
  • Enable logging on network devices surrounding ICS environments and alert on unexpected connection attempts to PLC endpoints.
  • Subscribe to Rockwell Automation and ICS-CERT advisories to receive timely notification of newly disclosed vulnerabilities.