- What is CVE-2021-42260?
- Rockwell Automation recommends updating affected controllers to the following minimum firmware versions: ControlLogix 5580 and GuardLogix 5580 to version 34.015 and later; CompactLogix 5380, Compact GuardLogix 5380, and CompactLogix 5480 to version 37.011 and later. As a defensive mitigation, CISA recommends minimizing network exposure for control system devices, ensuring they are not internet-accessible, locating control system networks behind firewalls, and isolating them from business networks. When remote access is required, use VPNs updated to the most current version. Perform proper impact analysis and risk assessment before deploying defensive measures.
- How severe is CVE-2021-42260?
- high, CVSS 7.5
- Is CVE-2021-42260 known to be exploited?
- It is not marked known-exploited in this record.
- How should CVE-2021-42260 be mitigated?
- Rockwell Automation recommends updating affected controllers to the following minimum firmware versions: ControlLogix 5580 and GuardLogix 5580 to version 34.015 and later; CompactLogix 5380, Compact GuardLogix 5380, and CompactLogix 5480 to version 37.011 and later. As a defensive mitigation, CISA recommends minimizing network exposure for control system devices, ensuring they are not internet-accessible, locating control system networks behind firewalls, and isolating them from business networks. When remote access is required, use VPNs updated to the most current version. Perform proper impact analysis and risk assessment before deploying defensive measures.