Rockwell Automation Arena
cpe:2.3:a:rockwellautomation:arena_simulation:*:*:*:*:*:*:*, +1 more
- <= 16.20.08
A local code execution vulnerability has been identified in Rockwell Automation Arena versions through 16.20.08. This vulnerability allows a threat actor to write outside of the allocated memory buffer, leading to the execution of arbitrary code and the potential disclosure of information. The issue arises from improper validation of user-supplied data. Exploitation of this vulnerability requires a legitimate user to open a malicious DOE file.
Exploitation of this vulnerability could result in unauthorized information disclosure and the execution of arbitrary code on the affected system.
Users can upgrade to Arena version 16.20.09 or later to address this vulnerability. For those unable to upgrade, Rockwell Automation recommends applying general security best practices where possible.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.