Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a malicious DOE file.
oryginał ENCVSS Vector
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XRockwellautomation Arena
APPRockwellautomation< 16.20.11
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
RCEMemory
CWE
Powiązane podatności
CVE-2026-8313HIGH7.0PL ✓ten sam produkt
Rockwell Automation Arena – out-of-bounds write w komponencie linker.exe (Siman)
CVE-2026-8314HIGH7.0PL ✓ten sam produkt
Rockwell Automation Arena: out-of-bounds write umożliwiający RCE
CVE-2026-8085HIGH7.0PL ✓ten sam produkt
RCE poprzez out-of-bounds write w Rockwell Automation Arena Simulation
CVE-2026-8312HIGH7.0PL ✓ten sam produkt
RCE w Rockwell Automation Arena — out-of-bounds write w expmt.exe
CVE-2025-7032HIGH8.4ten sam produkt
A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simula...