A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product
that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page.
Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2023-32627 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page. |
Solution
Customers should disable the webserver during normal use. The webserver is disabled by default and should only be enabled to modify configurations. After modifying configurations, the web server should be disabled.
Workaround
No workaround given by the vendor.
Fri, 24 Jan 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: Rockwell
Published:
Updated: 2025-01-24T16:15:52.659Z
Reserved: 2023-03-29T20:07:06.685Z
Link: CVE-2023-29022

Updated: 2024-08-02T14:00:14.779Z

Status : Modified
Published: 2023-05-11T18:15:13.023
Modified: 2025-01-24T17:15:11.670
Link: CVE-2023-29022

No data.

No data.