AI analysis
Rockwell Automation's ArmorStart LT distributed motor controller contains a denial-of-service flaw in its embedded web server, classified as CWE-770 (allocation of resources without limits). A remote, unauthenticated attacker can trigger it by sending a single specially crafted HTTP PUT request to the device's web interface, per the CVSS 4.0 vector (network attack vector, no privileges or user interaction required). The result is a crash or hang of the web server and loss of the device's web management interface; the CVSS scoring indicates no confidentiality or integrity impact and no impact on downstream systems. Organizations running ArmorStart LT motor controllers, typically in plant-floor OT networks, are affected, especially where the embedded web server is reachable from untrusted networks. No public proof-of-concept or known exploitation exists, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
What to do: Check the Rockwell Automation security advisory for affected and fixed firmware versions (not specified in the available data) and plan a firmware update when releases are identified. Until then, restrict HTTP access to ArmorStart LT web servers to trusted management networks using firewall rules, ACLs, or network segmentation, and avoid exposing the embedded web server directly to the internet. Monitor devices for unexplained web interface outages, which would indicate possible exploitation attempts.
Affected
| Rockwell Automation ArmorStart LT (distributed motor controller with embedded web server) | — |
Estimated exposure
nicheunknown; plausibly on the order of tens of thousands of deployed devices worldwide, of which only a small fraction is internet-exposed — No public install-base counts or scan data are provided in the source material; ArmorStart LT is a niche line of distributed motor controllers deployed mainly inside industrial OT networks that are usually segmented from the internet, so…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.