Description
A denial-of-service security issue exists within ArmorStart® LT. The security issue stems from improper handling of a crafted HTTP PUT request sent to the embedded web server. This can result in a loss of web server availability
Published: 2026-09-01
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A denial‑of‑service issue exists in Rockwell Automation ArmorStart® LT caused by improper handling of a specially crafted HTTP PUT request sent to the embedded web server. The flaw allows an adversary to cause the web server to become unavailable, interrupting management and monitoring functions. The weakness is identified as CWE‑770, indicating failure to manage system resources correctly.

Affected Systems

The vulnerability affects Rockwell Automation ArmorStart® LT devices running version v2.001 and earlier. The vendor recommends upgrading to version v2.002 or later to contain the flaw.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, and while the EPSS score is currently unavailable, the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, via network access to the embedded web server. An attacker who can reach the device can send the crafted PUT request to trigger the denial of service, potentially forcing a reboot or halting service, and thereby denying legitimate users access to essential system configuration and monitoring.

Generated by OpenCVE AI on September 1, 2026 at 15:58 UTC.

Remediation

Vendor Solution

Upgrade to version   v2.002 https://compatibility.rockwellautomation.com/Pages/Downloads.aspx  or later.


OpenCVE Recommended Actions

  • Upgrade ArmorStart® LT to version v2.002 or later according to the vendor’s recommendation
  • Disable or restrict HTTP PUT methods on the embedded web server to mitigate exploitation until a patch is applied
  • Segregate network access by implementing firewall rules that allow only trusted IPs to reach the embedded web server

Generated by OpenCVE AI on September 1, 2026 at 15:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation armorstart Lt
Vendors & Products Rockwellautomation
Rockwellautomation armorstart Lt

Tue, 01 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description A denial-of-service security issue exists within ArmorStart® LT. The security issue stems from improper handling of a crafted HTTP PUT request sent to the embedded web server. This can result in a loss of web server availability
Title Rockwell Automation ArmorStart® LT Denial Of Service
First Time appeared Rockwell Automation
Rockwell Automation armorstart Lt
Weaknesses CWE-770
CPEs cpe:2.3:a:rockwell_automation:armorstart_lt:v2.001_and_below:*:*:*:*:*:*:*
Vendors & Products Rockwell Automation
Rockwell Automation armorstart Lt
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Rockwell Automation Armorstart Lt
Rockwellautomation Armorstart Lt
cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-09-01T15:41:10.230Z

Reserved: 2026-08-10T14:37:21.513Z

Link: CVE-2026-19472

cve-icon Vulnrichment

Updated: 2026-09-01T15:41:07.393Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T13:18:12.857

Modified: 2026-09-01T20:50:01.960

Link: CVE-2026-19472

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T16:00:13Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling