CVE-2026-19472
8.7Rockwell · ArmorStart LT
A denial of service vulnerability in the Rockwell ArmorStart LT embedded web server allows unauthenticated attackers to cause a service outage via a crafted HTTP PUT request.
Executive summary
A high severity denial of service vulnerability in Rockwell ArmorStart LT allows unauthenticated attackers to crash the web server, necessitating an immediate firmware update.
Vulnerability
The vulnerability is caused by improper handling of resources during HTTP PUT requests (CWE-770), which allows an unauthenticated attacker to exhaust system resources and render the web server unresponsive.
Business impact
The ability for an unauthenticated remote attacker to cause a denial of service on industrial control infrastructure presents a significant operational risk. Successful exploitation results in the loss of remote management capabilities for the affected hardware, which can disrupt industrial processes and lead to costly unplanned downtime. With a CVSS score of 8.7, this vulnerability demands immediate attention to ensure the availability of critical operational technology.
Remediation
Immediate Action: Upgrade the ArmorStart LT firmware to version v2.002 or later as documented in the Rockwell Automation security advisory.
Proactive Monitoring: Monitor network traffic for anomalous HTTP PUT requests directed at industrial control device web interfaces and review device logs for service crashes or restarts.
Compensating Controls: Restrict network access to the embedded web server by placing the device behind a secure firewall or utilizing an isolated management network to prevent unauthorized access.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high severity of this vulnerability and the potential for operational disruption, administrators should prioritize patching all affected ArmorStart LT units. Apply the vendor-provided firmware update to version v2.002 immediately to remediate the resource allocation flaw and prevent potential denial of service attacks.