ZeroHour
Product

ArmorStart LT

0 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Rockwell Automation ArmorStart LT

CISA flags two flaws (CVE-2026-19471, CVE-2026-19472) in Rockwell Automation ArmorStart LT <=v2.001: stored XSS and web server denial-of-service.

Rockwell Automation reported two issues in the embedded web server of ArmorStart LT v2.001 and earlier. CVE-2026-19471 involves multiple stored cross-site scripting flaws (CVSS 7.3) where unsanitized input is stored server-side and executes in other users' browsers. CVE-2026-19472 is a denial-of-service issue (CVSS 7.5) triggered by a crafted HTTP PUT request that exhausts web server resources. No public exploitation has been reported to CISA.

Rockwell Automation security advisory (AV26-869)

Canada's Cyber Centre flags vulnerabilities across multiple Rockwell Automation ICS products including ControlLogix 5580 and RSLinx Classic.

Canadian Centre for Cyber Security advisory AV26-869, dated September 1, 2026, lists vulnerabilities in Rockwell Automation products: 1756-ENBT Module (all versions), ArmorStart LT (v2.001 and earlier), CompactLogix 5380 / ControlLogix 5580 (V33 and earlier plus several V34-V36 releases), and RSLinx Classic (V4.50 and earlier). It references Rockwell advisories SD1792, SD1794, SD1797, and SD1798 and urges users to apply updates as available.

Canadian Centre for Cyber Security · 14d agoAdvisory

Related CVEs

  • Unauthenticated DoS in Rockwell Automation ArmorStart LT embedded web server
    Rockwell Automation's ArmorStart LT distributed motor controller contains a denial-of-service flaw in its embedded web server, classified as CWE-770 (allocation of resources without limits). A remote, unauthenticated attacker can trigger it by sending a single specially crafted HTTP PUT request to the device's web interface, per the CVSS 4.0 vector (network attack vector, no privileges or user interaction required). The result is a crash or hang of the web server and loss of the device's web management interface; the CVSS scoring indicates no confidentiality or integrity impact and no impact on downstream systems. Organizations running ArmorStart LT motor controllers, typically in plant-floor OT networks, are affected, especially where the embedded web server is reachable from untrusted networks. No public proof-of-concept or known exploitation exists, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
    · Rockwell Automation ArmorStart LT (distributed motor controller with embedded web server)niche
  • Stored XSS in Rockwell Automation ArmorStart LT
    CVE-2026-19471 describes multiple stored cross-site scripting (XSS) flaws in Rockwell Automation's ArmorStart LT, caused by user-supplied input that is not properly sanitized before being stored on the device. An attacker can inject malicious scripts into stored fields, and those scripts execute in the browser of any user who later views the affected page in the device's interface. Per the CVSS 4.0 vector, the attack is carried out over the network and requires no privileges or user interaction beyond viewing the stored content, but the rated impact is limited (low impact to confidentiality, integrity, and availability), meaning an attacker could typically run scripts in other users' sessions within the product's interface rather than compromise the broader system. Affected users are organizations running ArmorStart LT distributed motor-control units whose management or web interfaces are accessed by operators and engineers. As of now there is no known public proof of concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
    · Rockwell Automation ArmorStart LTniche

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.