VYPR
Unrated severityNVD Advisory· Published May 11, 2023· Updated Jan 24, 2025

Rockwell Automation ArmorStart ST Vulnerable to Cross-Site Scripting Attack

CVE-2023-29022

Description

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product

that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An XSS vulnerability in Rockwell Automation ArmorStart ST allows an admin attacker to view user data, modify the web interface, and disrupt availability.

Vulnerability

A cross-site scripting (XSS) vulnerability exists in Rockwell Automation's ArmorStart ST product (models 281E and 284EE) [1]. The flaw enables a malicious user with administrator privileges and network access to inject malicious scripts into the web interface [1]. The exact affected firmware versions are not detailed in the available references, but the advisory covers these product lines [1].

Exploitation

An attacker must have administrator-level credentials and network connectivity to the ArmorStart ST device [1]. With these prerequisites, the attacker can inject a crafted payload into the web application through an input field or parameter that is not properly sanitized [1]. No user interaction is required beyond the attacker's own admin session [1].

Impact

Successful exploitation allows the attacker to view sensitive user data, modify the appearance or content of the web interface, and potentially cause interruptions to the availability of the web page [1]. The impact is limited to the scope of the web interface and does not extend to control logic or field device operations according to the advisory [1].

Mitigation

Rockwell Automation has released a security advisory (publication ID 1139438) addressing these vulnerabilities [1]. Users should review the advisory, apply any recommended firmware updates or configuration changes, and restrict administrative access to trusted networks. If no patch is explicitly listed in the advisory, users should contact Rockwell Automation support for remediation guidance [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.