A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product

that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page.



Advisories
Source ID Title
EUVD EUVD EUVD-2023-32630 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page.
Fixes

Solution

Customers should disable the webserver during normal use. The webserver is disabled by default and should only be enabled to modify configurations. After modifying configurations, the web server should be disabled.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2024-08-02T14:00:14.643Z

Reserved: 2023-03-29T20:07:06.686Z

Link: CVE-2023-29025

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-05-11T18:15:13.323

Modified: 2024-11-21T07:56:25.007

Link: CVE-2023-29025

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.