CVE-2026-19472
Received Received - Intake

Denial of Service in ArmorStart LT via HTTP PUT Request

Vulnerability report for CVE-2026-19472, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Rockwell Automation

Description

A denial-of-service security issue exists within ArmorStart® LT. The security issue stems from improper handling of a crafted HTTP PUT request sent to the embedded web server. This can result in a loss of web server availability

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
rockwellautomation armorstart_lt *
rockwell_automation armorstart_lt to 2.002 (exc)
rockwell_automation armorstart_lt v2.002

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a denial-of-service vulnerability in ArmorStart LT motor controllers. It occurs when a specially crafted HTTP PUT request is sent to the device's embedded web server. The server mishandles this request, causing it to become unavailable and disrupt normal operations.

Detection Guidance

Monitor network traffic for unusual HTTP PUT requests targeting ArmorStart LT devices. Check firmware versions of affected devices (v2.001 or below). Use intrusion detection systems to flag malformed HTTP requests.

Impact Analysis

The vulnerability can cause loss of web server availability on affected ArmorStart LT devices. This may disrupt normal operations, prevent remote monitoring or control, and lead to downtime in industrial systems using these controllers.

Compliance Impact

This vulnerability could impact compliance with standards like GDPR and HIPAA by disrupting the availability of critical systems. A denial-of-service condition may lead to unauthorized access or data processing delays, potentially violating availability requirements in these regulations.

Mitigation Strategies

Upgrade firmware to v2.002 or later for affected devices (catalog numbers Bul 290E, 291E, 294E). Isolate vulnerable devices from critical network segments. Apply network-level protections to block malicious HTTP PUT requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19472. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart