ZeroHour

CVE-2026-19471

niche

Stored XSS in Rockwell Automation ArmorStart LT

CVSS 4.0
6.9 medium
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-19471 describes multiple stored cross-site scripting (XSS) flaws in Rockwell Automation's ArmorStart LT, caused by user-supplied input that is not properly sanitized before being stored on the device. An attacker can inject malicious scripts into stored fields, and those scripts execute in the browser of any user who later views the affected page in the device's interface. Per the CVSS 4.0 vector, the attack is carried out over the network and requires no privileges or user interaction beyond viewing the stored content, but the rated impact is limited (low impact to confidentiality, integrity, and availability), meaning an attacker could typically run scripts in other users' sessions within the product's interface rather than compromise the broader system. Affected users are organizations running ArmorStart LT distributed motor-control units whose management or web interfaces are accessed by operators and engineers. As of now there is no known public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.

What to do: Monitor the Rockwell Automation security advisory ([email protected]) for the affected version ranges and fixed firmware, and apply the vendor's update when released. In the meantime, restrict access to ArmorStart LT management interfaces to trusted personnel, limit or avoid browser access to the device UI from untrusted endpoints, and ensure the units are segmented from untrusted networks. Because impact is limited to script execution in users' browsers, standard web-session hygiene and network segmentation substantially reduce risk.

Affected
Rockwell Automation ArmorStart LT
Estimated exposure
nichelikely on the order of thousands of installed units across industrial plants, with only a small subset reachable beyond the plant network (estimate; no public… — ArmorStart LT is a specialized distributed motor-control product line deployed as individual nodes on industrial OT networks rather than as internet-facing mass-market software, so the plausible install base is in the thousands of devices…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker to inject malicious scripts that will be executed when other users access the affected page.

Weakness
CWE-79
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Rockwell Automation ArmorStart LT

CISA flags two flaws (CVE-2026-19471, CVE-2026-19472) in Rockwell Automation ArmorStart LT <=v2.001: stored XSS and web server denial-of-service.

Rockwell Automation reported two issues in the embedded web server of ArmorStart LT v2.001 and earlier. CVE-2026-19471 involves multiple stored cross-site scripting flaws (CVSS 7.3) where unsanitized input is stored server-side and executes in other users' browsers. CVE-2026-19472 is a denial-of-service issue (CVSS 7.5) triggered by a crafted HTTP PUT request that exhausts web server resources. No public exploitation has been reported to CISA.