PT-2026-60348 · Rockwell Automation · Arena
CVE-2026-6071
·
Published
2026-07-15
·
Updated
2026-09-03
CVSS v4.0
7.5
High
| Vector | AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Rockwell Automation Arena Simulation (affected versions not specified)
Description
A remote code execution issue occurs during the parsing of DOE files. This flaw allows a remote attacker to perform an out-of-bounds write, which involves writing data past the end of an allocated object, potentially enabling the execution of arbitrary code within the context of the current process. Exploitation requires a legitimate user to open a malicious file or visit a malicious page.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Arena