CVE-2023-29023 is a cross-site scripting (XSS) vulnerability affecting Rockwell Automation's ArmorStart ST products. This flaw could allow an attacker to view or modify sensitive data, or render the web page unavailable. It carries a CVSS score of 6.1 (Medium) due to its network attack vector and low attack complexity, though user interaction (e.g., phishing) is required for successful exploitation. There is no evidence of active exploitation, nor publicly available exploit code, but it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:rockwellautomation:armorstart_st_284ee_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:rockwellautomation:armorstart_st_281e_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.