Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix
September 1, 2026 · CISA (US-CERT) · Severity: CRITICAL
View CSAF Summary The following versions of Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix are affected: ControlLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) GuardLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) CompactLogix 5380 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) Compact GuardLogix 5380 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) CompactLogix 5480 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix Loop with Unreachable Exit Condition ('Infinite Loop') Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2021-42260 A potential denial of service vulnerability exists in the affected products and can be triggered via corrupt crafted data. This could result in a major nonrecoverable fault (MNRF). A program download is required to recover safety controllers. For non-safety controllers, a stage 2 reset is required to recover. View CVE Details Affected Products Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix Vendor:Rockwell Automation Product Version:Rockwell Automation ControlLogix 5580 <34.015, Rockwell Automation ControlLogix 5580 <35.014, Rockwell Automation ControlLogix 5580 <36.013, Rockwell Automation ControlLogix 5580 <37.011, Rockwell Automation GuardLogix 5580 <34.015, Rockwell Automation...
Key Takeaways
- CISA published an advisory for Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, and Compact GuardLogix programmable logic controllers.
- Affected versions include ControlLogix 5580 releases below 34.015, 35.014, 36.013, and 37.011, referencing CVE-2021-42260 across the product line.
- Operators should update affected Rockwell Logix controllers to patched firmware versions and review the CSAF advisory for mitigations.