Rockwell Automation ArmorStart LT

MonitorCVSS 7.5ICS-CERT ICSA-26-246-04Sep 1, 2026
Rockwell Automation
Summary

Rockwell ArmorStart LT devices contain multiple vulnerabilities that allow remote attackers to compromise device functionality without authentication. The vulnerabilities exist in all versions of the product, and Rockwell Automation has not released a patch. The high CVSS score (7.5) reflects the ease of exploitation and potential impact on critical motor control operations.

What this means
What could happen
An attacker with network access to an ArmorStart LT device could execute arbitrary code or disrupt its soft starter functionality, potentially causing uncontrolled motor starts or process interruptions in production equipment.
Who's at risk
Facilities operating Rockwell ArmorStart LT soft starters should care, including manufacturing plants, water treatment facilities, and electric utilities using these devices for motor control. Any process that depends on controlled motor starts could be affected.
How it could be exploited
An attacker on the network could send specially crafted packets to the ArmorStart LT's network interface. The device does not properly validate input, allowing the attacker to execute commands or alter device behavior remotely without credentials.
Prerequisites
  • Network access to ArmorStart LT device (likely Ethernet port 502 or proprietary port)
  • No authentication credentials required
remotely exploitableno authentication requiredno patch availablenetwork-accessible device
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (1)
ProductAffected VersionsFix Status
ArmorStart LTAll versionsNo fix (EOL)
Remediation & Mitigation
0/5
Do now
0/3
HARDENINGIsolate ArmorStart LT devices on a separate industrial network segment with firewall rules blocking unauthorized access from corporate networks and the internet
HARDENINGRestrict network access to ArmorStart LT devices to only authorized engineering workstations and control systems that need to communicate with them
WORKAROUNDDisable any unnecessary remote management or diagnostic features on ArmorStart LT devices if available
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HARDENINGMonitor network traffic to and from ArmorStart LT devices for anomalous patterns or unauthorized access attempts
WORKAROUNDContact Rockwell Automation for guidance on interim compensating controls or evaluate migration to a supported soft starter product with security patches available
API: /api/v1/advisories/7b9c0c1c-8e3f-45fb-bf97-c1df962a96ae

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.