CVE-2026-19472 Overview
CVE-2026-19472 is a denial-of-service vulnerability affecting Rockwell Automation ArmorStart LT industrial motor control devices. The flaw resides in the embedded web server, which improperly handles a crafted HTTP PUT request. An unauthenticated remote attacker can send a malicious request to disrupt web server availability on the device. The issue is classified under [CWE-770] Allocation of Resources Without Limits or Throttling.
Critical Impact
A single crafted HTTP PUT request to the embedded web server can cause a loss of web server availability on affected ArmorStart LT devices, disrupting operator access to device management functions in industrial environments.
Affected Products
- Rockwell Automation ArmorStart LT (see vendor advisory for affected firmware versions)
- Embedded web server component of the ArmorStart LT product family
- Refer to the Rockwell Automation Security Advisory SD1797 for the full list of impacted versions
Discovery Timeline
- 2026-09-01 - CVE-2026-19472 published to the National Vulnerability Database
- 2026-09-01 - Last updated in NVD database
Technical Details for CVE-2026-19472
Vulnerability Analysis
The vulnerability affects the HTTP handling logic of the embedded web server running on ArmorStart LT devices. When the server receives a specifically crafted HTTP PUT request, it fails to correctly validate or bound the request handling. This causes the web server process to become unresponsive, resulting in a denial-of-service condition.
The issue maps to [CWE-770], which describes allocation of resources without limits or throttling. An attacker who can reach the device over the network does not need credentials or user interaction to trigger the condition. In operational technology environments, loss of the embedded web server disrupts remote configuration, diagnostics, and monitoring capabilities exposed by the device.
Root Cause
The root cause is improper handling of a crafted HTTP PUT request within the embedded web server. The server does not enforce sufficient validation, resource limits, or error handling on the incoming request. Attackers exploit this gap to exhaust server resources or force the service into an unrecoverable state.
Attack Vector
Exploitation requires network reachability to the embedded web server on the ArmorStart LT device. The attacker sends a single crafted HTTP PUT request to the target. No authentication, privileges, or user interaction are required. The impact is limited to availability of the web server; confidentiality and integrity are not directly affected according to the CVSS 4.0 metrics published by the vendor.
No public proof-of-concept exploit code is available. Refer to the Rockwell Automation Security Advisory SD1797 for vendor technical detail.
Detection Methods for CVE-2026-19472
Indicators of Compromise
- Unexpected unavailability or crash of the embedded web server on ArmorStart LT devices
- Inbound HTTP PUT requests to ArmorStart LT devices from unexpected internal or external sources
- Repeated connection failures or timeouts when accessing device management interfaces
- Device reboots or watchdog resets correlated with anomalous HTTP traffic
Detection Strategies
- Monitor network traffic for HTTP PUT requests directed at ArmorStart LT device IP addresses
- Deploy network intrusion detection signatures for anomalous HTTP methods against industrial control system (ICS) assets
- Alert on availability changes for embedded web services in operational technology (OT) network segments
- Correlate device unresponsiveness events with recent HTTP traffic patterns using centralized log analytics
Monitoring Recommendations
- Ingest network flow and OT protocol telemetry into a centralized data lake for cross-source correlation
- Track baseline HTTP request patterns to ArmorStart LT devices and alert on deviations
- Enable device health monitoring on programmable logic controllers (PLCs) and motor controllers to detect service outages promptly
- Review firewall and access control logs for unauthorized attempts to reach device management ports
How to Mitigate CVE-2026-19472
Immediate Actions Required
- Apply the security update published in the Rockwell Automation Security Advisory SD1797
- Restrict network access to ArmorStart LT device management interfaces to authorized engineering workstations only
- Segment OT networks from IT networks and the internet using firewalls and demilitarized zones (DMZs)
- Inventory all ArmorStart LT devices and identify firmware versions requiring remediation
Patch Information
Rockwell Automation has published remediation guidance in advisory SD1797. Consult the Rockwell Automation Security Advisory for the fixed firmware version and upgrade instructions specific to your ArmorStart LT hardware revision.
Workarounds
- Block untrusted sources from reaching TCP port 80 or 443 on ArmorStart LT devices using network access control lists
- Disable the embedded web server if not required for operational workflows
- Place vulnerable devices behind an OT-aware firewall that filters HTTP methods and enforces rate limits
- Require VPN or jump host access for any device management activity
# Example firewall rule to restrict HTTP access to ArmorStart LT devices
# Replace <ARMORSTART_IP> and <ENGINEERING_WORKSTATION_IP> with actual values
iptables -A FORWARD -p tcp -s <ENGINEERING_WORKSTATION_IP> -d <ARMORSTART_IP> --dport 80 -j ACCEPT
iptables -A FORWARD -p tcp -d <ARMORSTART_IP> --dport 80 -j DROP
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
