Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
High

DoS in Rockwell Automation ArmorStart LT (Achilles Comprehensive step limit storm reboot)

IdentifiersCVE-2025-9281CWE-400· Uncontrolled Resource Consumption

CVE-2025-9281 is a denial-of-service vulnerability in Rockwell Automation ArmorStart® LT devices. When the device is subjected to the Achilles Comprehensive step limit storm test traffic, it can reboot unexpectedly, resulting in loss of availability. The weakness is classified as uncontrolled resource consumption (CWE-400) and is remotely triggerable over the network (CVSS v3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H; CVSS v4.0 also indicates AV:N/AC:L/PR:N/UI:N with high availability impact). Affected ArmorStart LT models include 290D/291D/294D running versions up to and including V2.002 (per the republished Rockwell advisory SD1768/CISA notice context).

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows an unauthenticated remote attacker to cause a denial-of-service condition by forcing the device to reboot, disrupting availability of the ArmorStart LT and potentially interrupting dependent industrial operations. Availability impact is high; confidentiality and integrity impacts are reported as none in the provided scoring vectors.

Mitigation

If you can’t patch tonight, do this now.

From the provided CISA/ICS guidance: minimize network exposure of control system devices, ensure they are not internet-accessible, place control networks/remote devices behind firewalls and isolate them from business networks, and use secure remote access methods (e.g., VPN) kept up to date. Additionally, avoid executing Achilles Comprehensive step limit storm tests against production devices and limit exposure to untrusted/high-rate traffic sources where feasible.

Remediation

Patch, then assume compromise.

The provided content does not include a fixed version or specific vendor patch/remediation steps for CVE-2025-9281 beyond referencing Rockwell Automation advisory SD1768. Track SD1768 for updated remediation guidance and apply any vendor-provided firmware update or corrective action when released.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Rockwell AutomationArmorstart Lt Firmwareoperating_system

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity2

Community discussion across Reddit, Mastodon, and other social sources.