VYPR
Unrated severityNVD Advisory· Published May 11, 2023· Updated Jan 24, 2025

Rockwell Automation ArmorStart ST Vulnerable to Cross-Site Scripting Attack

CVE-2023-29026

Description

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product

that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Rockwell Automation ArmorStart ST allows admins with network access to view user data, modify the web interface, or disrupt availability.

Vulnerability

A cross-site scripting (XSS) vulnerability exists in Rockwell Automation's ArmorStart ST product (281E, 284EE). The flaw allows a malicious user with admin privileges and network access to inject arbitrary web scripts or HTML, leading to unauthorized viewing of user data and modification of the web interface [1]. The official description does not specify exact firmware versions, but affected devices should be assumed to include the listed product lines.

Exploitation

An attacker must possess valid administrator credentials for the ArmorStart ST device and have network connectivity to it. With these prerequisites, the attacker can craft and deliver a malicious script via a vulnerable input field or parameter; the script is then stored or reflected in the web interface, executing in the context of other users' browsers when the page is accessed [1].

Impact

Successful exploitation permits the attacker to view sensitive user data displayed within the web interface, modify the appearance or content of web pages, and potentially cause interruptions to the availability of those pages. The privilege level required is admin; the compromise is limited to the web interface layer of the affected device [1].

Mitigation

Rockwell Automation has not yet publicly disclosed a fixed version or release date in the available reference. Users should apply principle of least privilege to administrator accounts, restrict network access to the device's web interface to trusted users only, and monitor the vendor's advisory (linked in [1]) for forthcoming patches.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.