CVE-2025-9278 is a denial-of-service vulnerability affecting Rockwell Automation ArmorStart LT devices and their firmware. An unauthenticated attacker can trigger this condition by performing an active Burp Suite scan, leading to a loss of ICMP connectivity and rendering the web application inaccessible. With a CVSS score of 7.5 (High), this vulnerability is easily exploitable over the network with low attack complexity, resulting in a complete loss of availability. While there are no known public exploits or active exploitation, the vulnerability has garnered significant community discussion, indicating potential interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.002CPE matchmatch criteria | cpe:2.3:o:rockwellautomation:armorstart_lt_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.