VYPR

Arena

by Rockwellautomation

CVEs (46)

  • CVE-2024-11364HigDec 19, 2024
    risk 0.47cvss 7.3epss 0.00

    Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage…

  • CVE-2024-11157HigDec 19, 2024
    risk 0.47cvss 7.3epss 0.00

    A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this…

  • CVE-2024-11158MedDec 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable before it being initialized. If exploited, a threat actor could leverage…

  • CVE-2018-8843MedMay 14, 2018
    risk 0.36cvss 5.5epss 0.02

    Rockwell Automation Arena versions 15.10.00 and prior contains a use after free vulnerability caused by processing specially crafted Arena Simulation Software files that may cause the software application to crash, potentially losing any unsaved data..

  • CVE-2024-21920MedMar 26, 2024
    risk 0.29cvss 4.4epss 0.00

    A memory buffer vulnerability in Rockwell Automation Arena Simulation could potentially let a threat actor read beyond the intended memory boundaries. This could reveal sensitive information and even cause the application to crash, resulting in a denial-of-service condition.…

  • CVE-2019-13511LowAug 15, 2019
    risk 0.22cvss 3.3epss 0.06

    Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION EXPOSURE CWE-200. A maliciously crafted Arena file opened by an unsuspecting user may result in the limited exposure of information related to the targeted workstation.

Page 3 of 3