PT-2025-28960 · Rockwell Automation · Arena

CVE-2025-6376

·

Publicado

2025-07-09

·

Atualizado

2025-08-13

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Rockwell Automation Arena versions prior to 16.20.09
Description: A remote code execution issue exists in Rockwell Automation Arena. A crafted DOE file can force Arena Simulation to write beyond the boundaries of an allocated object. Exploitation requires user interaction, such as opening a malicious file within the software. If exploited, an attacker could execute arbitrary code on the target system. The software must run under the context of the administrator to cause a greater impact.
Recommendations: Update Rockwell Automation Arena to version 16.20.09. Avoid opening untrusted DOE files.

Correção

RCE

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-08441
CVE-2025-6376
ZDI-25-836

Produtos afetados

Arena