Rockwell Automation ArmorStart LT

Summary

Rockwell Automation ArmorStart LT versions less than or equal to v2.001 are affected by multiple stored cross-site scripting (XSS) vulnerabilities. Successful exploitation could lead to a loss of webserver availability or allow for script injection, which would execute when other users access affected pages.

IFF Assessment

FOE

The article details vulnerabilities that can be exploited by attackers, posing a direct threat to the availability and integrity of industrial control systems.

Severity

7.5 High

The CVSS score of 7.5 reflects the potential for attackers to inject malicious scripts, impacting confidentiality and integrity, with a focus on cross-site scripting vulnerabilities in web server functionality.

Defender Context

This alert highlights critical vulnerabilities in industrial control systems, specifically Rockwell Automation ArmorStart LT. Defenders should prioritize patching or implementing mitigations for affected versions to prevent cross-site scripting attacks that could compromise availability and allow script injection.

Read Full Story →