Executive brief
ArmorStart LT is a motor controller device used in industrial automation systems. A denial-of-service vulnerability in the embedded web server can be triggered by sending a specially crafted HTTP PUT request, causing the web interface to become unavailable and disrupting access to the device's configuration and monitoring capabilities.
Technical details
This is a resource exhaustion vulnerability (CWE-770) in the HTTP PUT request handler of the embedded web server in ArmorStart LT firmware versions 2.001 and below. The vulnerability stems from improper handling of crafted HTTP PUT requests, which can be exploited remotely without authentication to cause unbounded resource allocation and crash the web server. An attacker with network access to the device can trigger a denial of service by sending a specially crafted PUT request, resulting in loss of web server availability. The issue is fixed in firmware version 2.002.
Affected products
- Rockwell Automation ArmorStart LT v2.001 and below
Timeline
- 2026-09-01: disclosed
- 2026-09-01: patched: Corrected in firmware version 2.002