CVE-2025-2285
- EPSS 0.29%
- Veröffentlicht 08.04.2025 15:15:11
- Zuletzt bearbeitet 14.07.2025 19:14:19
A local code execution vulnerability exists in the Rockwell Automation Arena® due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitra...
CVE-2024-12175
- EPSS 0.25%
- Veröffentlicht 19.12.2024 21:15:07
- Zuletzt bearbeitet 13.03.2025 17:15:25
Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leve...
CVE-2024-12672
- EPSS 0.23%
- Veröffentlicht 19.12.2024 21:15:07
- Zuletzt bearbeitet 03.04.2025 16:36:30
A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary...
CVE-2024-11364
- EPSS 0.35%
- Veröffentlicht 19.12.2024 21:15:07
- Zuletzt bearbeitet 11.07.2025 20:03:34
Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a thre...
CVE-2024-11157
- EPSS 0.24%
- Veröffentlicht 19.12.2024 21:15:07
- Zuletzt bearbeitet 13.03.2025 16:15:15
A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary...
CVE-2024-12130
- EPSS 0.3%
- Veröffentlicht 05.12.2024 18:15:21
- Zuletzt bearbeitet 17.12.2024 15:52:01
An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat ac...
CVE-2024-11158
- EPSS 0.23%
- Veröffentlicht 05.12.2024 18:15:21
- Zuletzt bearbeitet 18.04.2025 18:15:37
An “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable before it being initialized. If exploited, a threat ...
CVE-2024-11156
- EPSS 0.24%
- Veröffentlicht 05.12.2024 18:15:21
- Zuletzt bearbeitet 17.12.2024 15:52:01
An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vuln...
CVE-2024-11155
- EPSS 0.23%
- Veröffentlicht 05.12.2024 18:15:20
- Zuletzt bearbeitet 14.04.2025 17:17:56
A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage ...
CVE-2024-2929
- EPSS 0.35%
- Veröffentlicht 26.03.2024 16:15:14
- Zuletzt bearbeitet 17.12.2024 16:14:25
A memory corruption vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code to the software by corrupting the memory triggering an access violation. Once inside, the threat...