Impact
A denial‑of‑service issue exists in Rockwell Automation ArmorStart® LT caused by improper handling of a specially crafted HTTP PUT request sent to the embedded web server. The flaw allows an adversary to cause the web server to become unavailable, interrupting management and monitoring functions. The weakness is identified as CWE‑770, indicating failure to manage system resources correctly.
Affected Systems
The vulnerability affects Rockwell Automation ArmorStart® LT devices running version v2.001 and earlier. The vendor recommends upgrading to version v2.002 or later to contain the flaw.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and while the EPSS score is currently unavailable, the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via network access to the embedded web server. An attacker who can reach the device can send the crafted PUT request to trigger the denial of service, potentially forcing a reboot or halting service, and thereby denying legitimate users access to essential system configuration and monitoring.
OpenCVE Enrichment