Independent perspective. Actionable security.Know what matters · Reduce exposure

Vulnerability Assurance / Intelligence

Denial of Service Vulnerability in Rockwell Automation PLC Product Lines

Source context: this article examines information published by the source on September 01, 2026. This site’s publication date is shown separately. Check the latest vendor guidance before acting.

What the vulnerability is

CVE-2021-42260 is a vulnerability characterized by a loop with an unreachable exit condition (CWE-835). It allows for a denial of service (DoS) state that can be triggered via corrupt crafted data. The result of this trigger is a major nonrecoverable fault (MNRF), which halts the operation of the affected controller.

Exposure and applicability

This vulnerability affects several Rockwell Automation programmable logic controller (PLC) product lines across multiple firmware branches. Specifically, the following hardware and version ranges are impacted:

  • ControlLogix 5580: Versions prior to 34.015, 35.014, 36.013, and 37.011.
  • GuardLogix 5580: Versions prior to 34.015, 35.014, 36.013, and 37.011.
  • CompactLogix 5380: Versions prior to 34.015, 35.014, 36.013, and 37.011.
  • Compact GuardLogix 5380: Versions prior to 34.015, 35.014, 36.013, and 37.011.
  • CompactLogix 5480: Versions prior to 34.015, 35.014, 36.013, and 37.011.

Remediation priorities

Our analysis suggests prioritizing remediation based on the controller’s role in safety-critical processes, as recovery requirements differ by device type. The primary corrective action is updating to the following firmware versions (or later) depending on the current branch:
* 34.015
* 35.014
* 36.013
* 37.011

For environments where immediate patching is not feasible, we recommend implementing compensating controls to reduce network exposure. This includes isolating control system networks from business networks using firewalls and ensuring that these devices are not accessible via the public internet. If remote access is required, it should be restricted to secure methods such as Virtual Private Networks (VPNs).

How to validate remediation

Verification of this mitigation requires more than a version check; defenders must ensure the update was successfully applied and the device remains operational within its intended state.

Because a trigger of this vulnerability results in an MNRF, recovery procedures are critical for validation planning:
* Non-safety controllers: Require a stage 2 reset to recover.
* Safety controllers: Require a full program download to recover.

Infrastructure owners should verify that the correct firmware version is reported by the device and that the necessary recovery tools (and current program backups for safety controllers) are available and tested, as these are required if a fault occurs during or after the update process.

Limits and open questions

Applying these firmware updates specifically addresses CVE-2021-42260; it does not provide a guarantee against all forms of denial of service attacks. There remains a residual risk for any system that cannot be patched due to legacy constraints, where the only available defenses are network isolation and perimeter security. It is currently unknown what specific types of “corrupt crafted data” trigger the loop, which limits the ability to create precise detection signatures for this specific entry path.

Source and editorial note

Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix · Source date: September 01, 2026 · Retrieved September 01, 2026.

Material facts are tied to the cited primary source. Recommendations are independent defensive analysis unless attributed to the source. Confirm consequential decisions against current authoritative guidance.

Request a Vulnerability Assessment

Turn security intelligence into action.

Discuss your exposure, priorities, and the evidence needed to validate the outcome.

Request a security assessment ↗

Turn security intelligence into action.

Understand exposure, prioritize the response, and define evidence for the outcome.

Request a Security Assessment