PatchSiren cyber security CVE debrief
CVE-2025-9466 Rockwell Automation CVE debrief
CVE-2025-9466 affects Rockwell Automation ArmorStart LT and can cause a denial-of-service condition. According to the CISA CSAF advisory published on 2026-01-29, execution of Achilles EtherNet/IP and CIP grammar tests may trigger an unexpected device reboot, taking the Link State Monitor down for several seconds. Rockwell Automation reported no patch or upgrade available at publication and recommended applying security best practices as a mitigation.
- Vendor
- Rockwell Automation
- Product
- ArmorStart LT 290D
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-29
- Original CVE updated
- 2026-01-29
- Advisory published
- 2026-01-29
- Advisory updated
- 2026-01-29
Who should care
OT/ICS operators, plant engineers, and security teams responsible for Rockwell Automation ArmorStart LT 290D, 291D, or 294D deployments should care most. Availability-focused defenders and anyone validating industrial Ethernet equipment with protocol test tools should treat this as a high-priority operational stability issue.
Technical summary
The advisory describes an availability-impacting fault in ArmorStart LT devices: during Achilles EtherNet/IP and CIP grammar testing, the device can reboot unexpectedly, which briefly drops the Link State Monitor. The published CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, reflecting network-reachable, low-complexity conditions with high availability impact and no confidentiality or integrity impact stated in the source.
Defensive priority
High for environments that use the affected ArmorStart LT models, especially where uninterrupted industrial network connectivity is important. The issue is limited to denial of service, but the lack of a patch at publication and the potential for operational disruption justify prompt mitigation planning.
Recommended defensive actions
- Confirm whether any ArmorStart LT 290D, 291D, or 294D devices are in use in your environment.
- Review Rockwell Automation advisory SD1768 and the associated CISA advisory for mitigation guidance.
- Apply Rockwell Automation's recommended security best practices to reduce exposure while no patch or upgrade is available.
- Limit unnecessary network access to affected devices and reduce opportunities for unauthenticated testing or scanning.
- Validate operational monitoring so brief link-state interruptions are detected and handled safely.
- Track vendor updates for a future corrective release or additional mitigation guidance.
Evidence notes
The source corpus states that a security issue exists within ArmorStart LT that can result in a denial-of-service condition and that the device reboots unexpectedly during Achilles EtherNet/IP and CIP grammar tests. The CSAF advisory lists affected products as ArmorStart LT 290D, 291D, and 294D, and the remediation section states there is no patch or upgrade at the time of publication. The advisory was republished by CISA from Rockwell Automation advisory SD1768 on 2026-01-29.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-9466 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-9466
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-9466 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-9466
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-029-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-029-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.