CVE-2023-29027: Rockwellautomation Armorstart St 281e Firmware

Medium severity, CVSS 5.9. EPSS: 0.6% chance of exploitation in the next 30 days.

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page.

Affected products

Published 2023-05-11. Last modified 2026-06-17.