A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2023-32636 | A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability. |
Fixes
Solution
Customers should disable the webserver during normal use. The webserver is disabled by default and should only be enabled to modify configurations. After modifying configurations, the web server should be disabled.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: Rockwell
Published:
Updated: 2024-08-02T14:00:14.782Z
Reserved: 2023-03-29T20:07:06.687Z
Link: CVE-2023-29031

No data.

Status : Modified
Published: 2023-05-11T18:15:13.843
Modified: 2024-11-21T07:56:25.720
Link: CVE-2023-29031

No data.

No data.