PatchSiren cyber security CVE debrief
CVE-2025-9281 Rockwell Automation CVE debrief
CVE-2025-9281 is a denial-of-service issue in Rockwell Automation ArmorStart LT. CISA’s 2026-01-29 advisory says the device can reboot unexpectedly during Achilles Comprehensive step limit storm tests, which causes the Link State Monitor to go down for several seconds. The advisory lists ArmorStart LT 290D, 291D, and 294D as affected and states that no patch or upgrade was available at publication, so operators should rely on Rockwell and CISA defensive guidance.
- Vendor
- Rockwell Automation
- Product
- ArmorStart LT 290D
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-29
- Original CVE updated
- 2026-01-29
- Advisory published
- 2026-01-29
- Advisory updated
- 2026-01-29
Who should care
Industrial control system owners, plant operators, maintenance teams, and security staff using ArmorStart LT 290D, 291D, or 294D should care most. Because the issue affects availability and can cause unexpected reboots, it is especially relevant in environments where short service interruptions can affect production or process continuity.
Technical summary
The source advisory describes an availability flaw in ArmorStart LT that can lead to a denial-of-service condition. The observed failure mode is an unexpected reboot during Achilles Comprehensive step limit storm testing, followed by the Link State Monitor being unavailable for several seconds. The advisory’s CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, and the affected products are ArmorStart LT 290D, 291D, and 294D. CISA’s publication also notes there is no patch or upgrade available at that time.
Defensive priority
High for OT availability and reliability. The issue is publicly documented, rated CVSS 7.5 High, and affects core uptime behavior in an industrial device. Prioritize if these models are deployed in production or where brief outages could disrupt operations.
Recommended defensive actions
- Confirm whether ArmorStart LT 290D, 291D, or 294D is deployed anywhere in your environment.
- Review Rockwell Automation advisory SD1768 and follow the vendor’s mitigation guidance.
- Apply CISA and Rockwell ICS security best practices, including segmentation and minimizing unnecessary exposure.
- Monitor affected assets for unexpected reboots and Link State Monitor drops.
- Plan operational contingencies for brief availability interruptions, such as redundancy or maintenance procedures where appropriate.
- Track vendor advisories for any future patch or update availability.
Evidence notes
Based on CISA CSAF advisory ICSA-26-029-02 republishing Rockwell Automation advisory SD1768 on 2026-01-29. The source text states: “A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive step limit storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.” The advisory lists affected products ArmorStart LT 290D, 291D, and 294D, and remediation text says there is no patch or upgrade at this time. The CVSS vector provided is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-9281 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-9281
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-9281 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-9281
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-029-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-029-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.