Rockwell Automation ControlLogix/CompactLogix/GuardLogix Denial of Service Vulnerability (CVE-2021-42260)
First seen Sep 2, 2026 · Updated Sep 2, 2026 · CVSS 7.5
A high-severity denial of service vulnerability affects multiple Rockwell Automation Logix controller families, including ControlLogix, CompactLogix, GuardLogix, and their variants. Exploitation via corrupt crafted data can trigger a major nonrecoverable fault (MNRF), requiring physical recovery actions such as program downloads or stage 2 resets. No public exploitation has been reported to date, and vendor firmware fixes are available.
Technical Analysis
CVE-2021-42260 is a Loop with Unreachable Exit Condition ('Infinite Loop', CWE-835) vulnerability affecting Rockwell Automation ControlLogix 5580, CompactLogix 5380/5480, GuardLogix 5580, and Compact GuardLogix 5380 controllers running firmware versions below 34.015, 35.014, 36.013, or 37.011 depending on family. An attacker with network access can send corrupt crafted data to the controller, causing an infinite loop condition that results in a major nonrecoverable fault (MNRF), effectively crashing the device and requiring manual recovery (program download for safety controllers, stage 2 reset for non-safety controllers). The vulnerability is remotely exploitable with low attack complexity and no authentication or user interaction required (CVSS 3.1: 7.5/High; CVSS 4.0: 8.7/High), though it impacts availability only, not confidentiality or integrity. This advisory targets industrial control system (OT) environments in critical manufacturing and has no direct plausible impact on AI agent systems, RAG pipelines, or LLM tool-use frameworks, as it concerns firmware-level denial of service in PLC hardware rather than IT/agent infrastructure.
Affected Systems
Rockwell Automation ControlLogix 5580 firmware <34.015, <35.014, <36.013, <37.011; GuardLogix 5580 firmware <34.015, <35.014, <36.013, <37.011; CompactLogix 5380 firmware <34.015, <35.014, <36.013, <37.011; Compact GuardLogix 5380 firmware <34.015, <35.014, <36.013, <37.011; CompactLogix 5480 firmware <34.015, <35.014, <36.013, <37.011
Indicators of Compromise
- No known IOCs published; no public exploitation reported at this time.
Remediation Steps
- 1
Apply vendor firmware updates
Update affected controllers to firmware version 34.015, 35.014, 36.013, or 37.011 (or later) as applicable to the specific product family.
- 2
Network segmentation
Minimize network exposure for all control system devices; ensure they are not accessible from the internet and are isolated behind firewalls from business networks.
- 3
Secure remote access
Use VPNs or other secure remote access methods when remote connectivity to control systems is required, keeping VPN software updated.
- 4
Follow vendor best practices
For systems that cannot be immediately updated, apply Rockwell Automation's published security best practices as a compensating control.
- 5
Incident reporting
Report any suspected malicious activity targeting these controllers to CISA for tracking and correlation.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.