Impact
ArmorStart® LT stores user supplied input on the server without proper sanitization, leading to stored cross‑site scripting. An attacker can embed malicious JavaScript that executes in the browsers of any user who views the affected page, potentially allowing session hijacking, credential theft, or arbitrary code execution in the victim’s context. The weakness is a classic reflected input handling flaw, classified as CWE‑79.
Affected Systems
The affected product is Rockwell Automation’s ArmorStart® LT, particularly versions 2.001 and earlier.
Risk and Exploitability
The vulnerability has a CVSS score of 6.9, indicating moderate severity. EPSS information is currently unavailable, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector requires an attacker to submit malicious input that is stored on the server, which generally implies the attacker must have legitimate user or privileged access to the system. From the available data, no exploitation conditions beyond this are identified.
OpenCVE Enrichment