Source context: this article examines information published by the source on September 01, 2026. This site’s publication date is shown separately. Check the latest vendor guidance before acting.
What the vulnerability is
CVE-2021-42260 is a vulnerability characterized by a loop with an unreachable exit condition (CWE-835). It allows for a denial of service (DoS) state that can be triggered via corrupt crafted data. The result of this trigger is a major nonrecoverable fault (MNRF), which halts the operation of the affected controller.
Exposure and applicability
This vulnerability affects several Rockwell Automation programmable logic controller (PLC) product lines across multiple firmware branches. Specifically, the following hardware and version ranges are impacted:
- ControlLogix 5580: Versions prior to 34.015, 35.014, 36.013, and 37.011.
- GuardLogix 5580: Versions prior to 34.015, 35.014, 36.013, and 37.011.
- CompactLogix 5380: Versions prior to 34.015, 35.014, 36.013, and 37.011.
- Compact GuardLogix 5380: Versions prior to 34.015, 35.014, 36.013, and 37.011.
- CompactLogix 5480: Versions prior to 34.015, 35.014, 36.013, and 37.011.
Remediation priorities
Our analysis suggests prioritizing remediation based on the controller’s role in safety-critical processes, as recovery requirements differ by device type. The primary corrective action is updating to the following firmware versions (or later) depending on the current branch:
* 34.015
* 35.014
* 36.013
* 37.011
For environments where immediate patching is not feasible, we recommend implementing compensating controls to reduce network exposure. This includes isolating control system networks from business networks using firewalls and ensuring that these devices are not accessible via the public internet. If remote access is required, it should be restricted to secure methods such as Virtual Private Networks (VPNs).
How to validate remediation
Verification of this mitigation requires more than a version check; defenders must ensure the update was successfully applied and the device remains operational within its intended state.
Because a trigger of this vulnerability results in an MNRF, recovery procedures are critical for validation planning:
* Non-safety controllers: Require a stage 2 reset to recover.
* Safety controllers: Require a full program download to recover.
Infrastructure owners should verify that the correct firmware version is reported by the device and that the necessary recovery tools (and current program backups for safety controllers) are available and tested, as these are required if a fault occurs during or after the update process.
Limits and open questions
Applying these firmware updates specifically addresses CVE-2021-42260; it does not provide a guarantee against all forms of denial of service attacks. There remains a residual risk for any system that cannot be patched due to legacy constraints, where the only available defenses are network isolation and perimeter security. It is currently unknown what specific types of “corrupt crafted data” trigger the loop, which limits the ability to create precise detection signatures for this specific entry path.
Source and editorial note
Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix · Source date: September 01, 2026 · Retrieved September 01, 2026.
Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.
Request a Vulnerability Assessment
Turn security intelligence into action.
Discuss your exposure, priorities, and the evidence needed to validate the outcome.
Request a security assessment ↗