A critical authentication bypass vulnerability, tracked as CVE-2021-22681, can be exploited by remote attackers to compromise programmable logic controllers (PLCs) manufactured by Rockwell Automation. The vulnerability was independently reported to Rockwell by researchers at the Soonchunhyang University in South Korea, Claroty, and Kaspersky. The issue resides in the Logix Designer software that uses a poorly protected private cryptographic key to verify communications with controllers. The flaw has received a CVSS score of 10, it affects the following products.”]
Source: https://securityaffairs.co/wordpress/115085/ics-scada/rockwell-automation-software-flaw.html

