PT-2025-28960 · Rockwell Automation · Arena
CVE-2025-6376
·
Publicado
2025-07-09
·
Atualizado
2025-08-13
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Rockwell Automation Arena versions prior to 16.20.09
Description:
A remote code execution issue exists in Rockwell Automation Arena. A crafted DOE file can force Arena Simulation to write beyond the boundaries of an allocated object. Exploitation requires user interaction, such as opening a malicious file within the software. If exploited, an attacker could execute arbitrary code on the target system. The software must run under the context of the administrator to cause a greater impact.
Recommendations:
Update Rockwell Automation Arena to version 16.20.09.
Avoid opening untrusted DOE files.
Correção
RCE
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Arena