Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a malicious DOE file.
CVSS Vector
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XRockwellautomation Arena
APPRockwellautomation< 16.20.11
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEMemory
CWE
Related vulnerabilities
CVE-2026-8313HIGH7.0PL ✓same product
Rockwell Automation Arena – out-of-bounds write w komponencie linker.exe (Siman)
CVE-2026-8314HIGH7.0PL ✓same product
Rockwell Automation Arena: out-of-bounds write umożliwiający RCE
CVE-2026-8085HIGH7.0PL ✓same product
RCE poprzez out-of-bounds write w Rockwell Automation Arena Simulation
CVE-2026-8312HIGH7.0PL ✓same product
RCE w Rockwell Automation Arena — out-of-bounds write w expmt.exe
CVE-2025-7032HIGH8.4same product
A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simula...