VYPR

Arena

by Rockwellautomation

CVEs (46)

  • CVE-2019-13510HigAug 15, 2019
    risk 0.52cvss 7.8epss 0.12

    Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. A maliciously crafted Arena file opened by an unsuspecting user may result in the application crashing or the execution of arbitrary code.

  • CVE-2026-8314HigJul 14, 2026
    risk 0.51cvss 7.3epss 0.00

    A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this…

  • CVE-2026-8313HigJul 14, 2026
    risk 0.51cvss 7.3epss 0.00

    A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this…

  • CVE-2026-8312HigJul 14, 2026
    risk 0.51cvss 7.3epss 0.00

    A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this…

  • CVE-2026-8085HigJul 14, 2026
    risk 0.51cvss 7.3epss 0.00

    A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this…

  • CVE-2025-7033HigAug 5, 2025
    risk 0.51cvss 7.8epss 0.00

    A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threat actor could execute…

  • CVE-2025-7032HigAug 5, 2025
    risk 0.51cvss 7.8epss 0.00

    A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threat actor could execute…

  • CVE-2025-7025HigAug 5, 2025
    risk 0.51cvss 7.8epss 0.00

    A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threat actor could execute…

  • CVE-2025-6377HigJul 9, 2025
    risk 0.51cvss 7.8epss 0.00

    A remote code execution security issue exists in the Rockwell Automation Arena®.  A crafted DOE file can force Arena Simulation to write beyond the boundaries of an allocated object. Exploitation requires user interaction, such as opening a malicious file within the…

  • CVE-2025-6376HigJul 9, 2025
    risk 0.51cvss 7.8epss 0.00

    A remote code execution security issue exists in the Rockwell Automation Arena®.  A crafted DOE file can force Arena Simulation to write beyond the boundaries of an allocated object. Exploitation requires user interaction, such as opening a malicious file within the…

  • CVE-2025-3289HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the…

  • CVE-2025-3288HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose…

  • CVE-2025-3287HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the…

  • CVE-2025-3286HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose…

  • CVE-2025-3285HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose…

  • CVE-2025-2829HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose…

  • CVE-2025-2293HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose…

  • CVE-2025-2288HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose…

  • CVE-2025-2287HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To…

  • CVE-2025-2286HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    A local code execution vulnerability exists in the Rockwell Automation Arena®  due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To…

Page 1 of 3