AI analysis
CVE-2026-19471 describes multiple stored cross-site scripting (XSS) flaws in Rockwell Automation's ArmorStart LT, caused by user-supplied input that is not properly sanitized before being stored on the device. An attacker can inject malicious scripts into stored fields, and those scripts execute in the browser of any user who later views the affected page in the device's interface. Per the CVSS 4.0 vector, the attack is carried out over the network and requires no privileges or user interaction beyond viewing the stored content, but the rated impact is limited (low impact to confidentiality, integrity, and availability), meaning an attacker could typically run scripts in other users' sessions within the product's interface rather than compromise the broader system. Affected users are organizations running ArmorStart LT distributed motor-control units whose management or web interfaces are accessed by operators and engineers. As of now there is no known public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
What to do: Monitor the Rockwell Automation security advisory ([email protected]) for the affected version ranges and fixed firmware, and apply the vendor's update when released. In the meantime, restrict access to ArmorStart LT management interfaces to trusted personnel, limit or avoid browser access to the device UI from untrusted endpoints, and ensure the units are segmented from untrusted networks. Because impact is limited to script execution in users' browsers, standard web-session hygiene and network segmentation substantially reduce risk.
Affected
| Rockwell Automation ArmorStart LT | — |
Estimated exposure
nichelikely on the order of thousands of installed units across industrial plants, with only a small subset reachable beyond the plant network (estimate; no public… — ArmorStart LT is a specialized distributed motor-control product line deployed as individual nodes on industrial OT networks rather than as internet-facing mass-market software, so the plausible install base is in the thousands of devices…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Multiple stored cross-site scripting security issues exist within ArmorStart® LT. Stored XSS occurs when user input is not properly sanitized and is stored on the server, allowing an attacker to inject malicious scripts that will be executed when other users access the affected page.