PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-9466 Rockwell Automation CVE debrief

CVE-2025-9466 affects Rockwell Automation ArmorStart LT and can cause a denial-of-service condition. According to the CISA CSAF advisory published on 2026-01-29, execution of Achilles EtherNet/IP and CIP grammar tests may trigger an unexpected device reboot, taking the Link State Monitor down for several seconds. Rockwell Automation reported no patch or upgrade available at publication and recommended applying security best practices as a mitigation.

Vendor
Rockwell Automation
Product
ArmorStart LT 290D
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-29
Original CVE updated
2026-01-29
Advisory published
2026-01-29
Advisory updated
2026-01-29

Who should care

OT/ICS operators, plant engineers, and security teams responsible for Rockwell Automation ArmorStart LT 290D, 291D, or 294D deployments should care most. Availability-focused defenders and anyone validating industrial Ethernet equipment with protocol test tools should treat this as a high-priority operational stability issue.

Technical summary

The advisory describes an availability-impacting fault in ArmorStart LT devices: during Achilles EtherNet/IP and CIP grammar testing, the device can reboot unexpectedly, which briefly drops the Link State Monitor. The published CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, reflecting network-reachable, low-complexity conditions with high availability impact and no confidentiality or integrity impact stated in the source.

Defensive priority

High for environments that use the affected ArmorStart LT models, especially where uninterrupted industrial network connectivity is important. The issue is limited to denial of service, but the lack of a patch at publication and the potential for operational disruption justify prompt mitigation planning.

Recommended defensive actions

  • Confirm whether any ArmorStart LT 290D, 291D, or 294D devices are in use in your environment.
  • Review Rockwell Automation advisory SD1768 and the associated CISA advisory for mitigation guidance.
  • Apply Rockwell Automation's recommended security best practices to reduce exposure while no patch or upgrade is available.
  • Limit unnecessary network access to affected devices and reduce opportunities for unauthenticated testing or scanning.
  • Validate operational monitoring so brief link-state interruptions are detected and handled safely.
  • Track vendor updates for a future corrective release or additional mitigation guidance.

Evidence notes

The source corpus states that a security issue exists within ArmorStart LT that can result in a denial-of-service condition and that the device reboots unexpectedly during Achilles EtherNet/IP and CIP grammar tests. The CSAF advisory lists affected products as ArmorStart LT 290D, 291D, and 294D, and the remediation section states there is no patch or upgrade at the time of publication. The advisory was republished by CISA from Rockwell Automation advisory SD1768 on 2026-01-29.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-9466 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-9466

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-9466 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-9466

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-029-02.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-029-02

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.