Description

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product

that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page.



Published: 2023-05-11
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Customers should disable the webserver during normal use. The webserver is disabled by default and should only be enabled to modify configurations. After modifying configurations, the web server should be disabled.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-32627 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page.
History

Fri, 24 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Rockwellautomation Armorstart St 281e Armorstart St 281e Firmware Armorstart St 284ee Armorstart St 284ee Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2025-01-24T16:15:52.659Z

Reserved: 2023-03-29T20:07:06.685Z

Link: CVE-2023-29022

cve-icon Vulnrichment

Updated: 2024-08-02T14:00:14.779Z

cve-icon NVD

Status : Modified

Published: 2023-05-11T18:15:13.023

Modified: 2025-01-24T17:15:11.670

Link: CVE-2023-29022

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses