Rockwell Automation ArmorStart LT Vulnerable to XSS and DoS Attacks
CISA has alerted users to two vulnerabilities in Rockwell Automation's ArmorStart LT, versions prior to v2.002, that could allow for script injection and denial-of-service conditions.

CISA has issued an advisory detailing two significant vulnerabilities affecting Rockwell Automation's ArmorStart LT industrial control system product. Versions prior to v2.002 are susceptible to exploitation, which could lead to a loss of web server availability or the execution of malicious scripts within user sessions.
The first vulnerability, identified as CVE-2026-19471, is a stored cross-site scripting (XSS) flaw. This type of vulnerability occurs when an application fails to properly sanitize user input before storing it. An attacker can inject malicious scripts into the system, which are then executed when other users access the affected web pages. This could lead to session hijacking, credential theft, or further compromise of the system.
The second vulnerability, CVE-2026-19472, is a denial-of-service (DoS) issue. Exploitation of this flaw is possible through a crafted HTTP PUT request sent to the device's embedded web server. A successful attack could render the web server unavailable, disrupting critical operations that rely on the ArmorStart LT device.
Rockwell Automation has acknowledged these vulnerabilities and has released firmware version v2.002 as a fix. The company strongly advises all users to update to the latest version to mitigate these risks. For organizations unable to upgrade immediately, Rockwell Automation recommends adhering to their established security best practices and consulting their official security advisories for further guidance.
The vulnerabilities have been assigned CVSS v3.1 base scores of 7.3 (HIGH) for the XSS flaw and 7.5 (HIGH) for the DoS vulnerability, indicating a significant risk to affected systems. The CVSS v4.0 scores are also high, with the DoS vulnerability rated at 8.7 (HIGH).
These vulnerabilities were reported to CISA by Rockwell Automation. CISA emphasizes the importance of minimizing network exposure for all control system devices, recommending they be isolated from the internet and protected by firewalls. Secure remote access methods, such as VPNs, should be utilized when necessary, ensuring they are kept up-to-date.
While no known public exploitation targeting these specific vulnerabilities has been reported to CISA at this time, the nature of these flaws in industrial control systems warrants prompt attention. Organizations are encouraged to perform thorough impact analyses and risk assessments before implementing any defensive measures.
This advisory highlights the ongoing need for vigilance in securing industrial control systems, as vulnerabilities in widely used products can have significant operational and security consequences.