Back

HIGH

Local Code Execution Vulnerability in Arena®

Published Apr 8, 2025

Description

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.

Affected products

Remediation

Vendor solution

Corrected in v.16.20.09 and later.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Rockwell
Published Apr 8, 2025
Updated Apr 8, 2025
Reserved Mar 26, 2025
CISA Vulnrichment
Updated Apr 8, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a