CVE-2021-42260
View CSAF Summary The following versions of Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix are affected: ControlLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) GuardLogix 5580 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) CompactLogix 5380 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) Compact GuardLogix 5380 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) CompactLogix 5480 <34.015, <35.014, <36.013, <37.011 (CVE-2021-42260, CVE-2021-42260, CVE-2021-42260, CVE-2021-42260) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix Loop with Unreachable Exit Condition ('Infinite Loop') Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2021-42260 A potential denial of service vulnerability exists in the affected products and can be triggered via corrupt crafted data. This could result in a major nonrecoverable fault (MNRF). A program download is required to recover safety controllers. For non-safety controllers, a stage 2 reset is required to recover. View CVE Details Affected Products Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix Vendor: Rockwell Automation Product Version: Rockwell Automation ControlLogix 5580 <34.015, Rockwell Automation ControlLogix 5580 <35.014, Rockwell Automation ControlLogix 5580 <36.013, Rockwell Automation ControlLogix 5580 <37.011, Rockwell Automation GuardLogix 5580 <34.015, Rockwell Automation GuardLogix 5580 <35.014, Rockwell Automation GuardLogix 5580 <36.013, Rockwell Automation GuardLog
CSIRTS triage
- What
- CVE-2021-42260 affects multiple Rockwell Automation PLC models across firmware versions.
- Who is affected
- Industrial control systems running the affected Rockwell Automation PLC models worldwide are at risk.
- Urgency
- Critical urgency given the CVSS 7.5 score and impact on critical infrastructure.
- Action
- Upgrade firmware to versions 34.015 or later, 35.014 or later, 36.013 or later, or 37.011 or later as appropriate for each device.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2021-42260
Get an email if CVE-2021-42260 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Moderate exploitation risk3.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 88% of all EPSS-scored CVEs.
Advisory coverage (2)
- medium[NEW] [medium] Rockwell Automation ControlLogix 5580, CompactLogix 5380, and CompactLogix 5480: Multiple vulne…cert-bund · 2026-09-02
- criticalRockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogixcisa · 2026-09-01
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2021-42260)