As cited
Copy frozen at (site build).
vulnerabilities
Rockwell Automation ArmorStart LT
Rockwell Automation ArmorStart LT versions 2.001 and earlier contain two vulnerabilities: CVE-2026-19471, a stored cross-site scripting (XSS) flaw that allows attackers to inject malicious scripts executed when users access affected pages, and CVE-2026-19472, a denial-of-service vulnerability triggered by crafted HTTP PUT requests that disable the web server. Firmware version 2.002 resolves both issues, with CVSS v3.1 scores of 7.3 and 7.5 respectively.
Why it matters: Industrial control system (ICS) operators and critical manufacturing facilities using ArmorStart LT must upgrade to firmware v2.002 immediately to prevent web server hijacking, script injection attacks, and availability loss in worldwide deployed systems.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Rockwell Automation ArmorStart LT
Rockwell Automation ArmorStart LT versions 2.001 and earlier contain two vulnerabilities: CVE-2026-19471, a stored cross-site scripting (XSS) flaw that allows attackers to inject malicious scripts executed when users access affected pages, and CVE-2026-19472, a denial-of-service vulnerability triggered by crafted HTTP PUT requests that disable the web server. Firmware version 2.002 resolves both issues, with CVSS v3.1 scores of 7.3 and 7.5 respectively.
Why it matters: Industrial control system (ICS) operators and critical manufacturing facilities using ArmorStart LT must upgrade to firmware v2.002 immediately to prevent web server hijacking, script injection attacks, and availability loss in worldwide deployed systems.
- Source published
- First seen by Cybersecurity Tracker