Junglewise Threat Intelligence

CVE-2026-19472: Rockwell Automation ArmorStart LT denial of service in HTTP PUT handler

CVE-2026-19472 · Severity: info · CVSS 7.5 · Published 2026-09-01

Vendors: Rockwell Automation.

Executive brief

ArmorStart LT is a motor controller device used in industrial automation systems. A denial-of-service vulnerability in the embedded web server can be triggered by sending a specially crafted HTTP PUT request, causing the web interface to become unavailable and disrupting access to the device's configuration and monitoring capabilities.

Technical details

This is a resource exhaustion vulnerability (CWE-770) in the HTTP PUT request handler of the embedded web server in ArmorStart LT firmware versions 2.001 and below. The vulnerability stems from improper handling of crafted HTTP PUT requests, which can be exploited remotely without authentication to cause unbounded resource allocation and crash the web server. An attacker with network access to the device can trigger a denial of service by sending a specially crafted PUT request, resulting in loss of web server availability. The issue is fixed in firmware version 2.002.

Affected products

  • Rockwell Automation ArmorStart LT v2.001 and below

Timeline

  • 2026-09-01: disclosed
  • 2026-09-01: patched: Corrected in firmware version 2.002

References

Related threats