VYPR
High severity7.8NVD Advisory· Published Apr 8, 2025· Updated Jun 17, 2026

CVE-2025-2287

CVE-2025-2287

Description

A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:rockwellautomation:arena:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:rockwellautomation:arena:*:*:*:*:*:*:*:*range: <16.20.09
    • (no CPE)
    • (no CPE)range: 16.20.08 and earlier

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.