Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mx5f-g28g-h8c4

Опубликовано: 09 июл. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 7.8

Описание

A remote code execution security issue exists in the Rockwell Automation Arena®.  A crafted DOE file can force Arena Simulation to write beyond the boundaries of an allocated object. Exploitation requires user interaction, such as opening a malicious file within the software. If exploited, a threat actor could execute arbitrary code on the target system. The software must run under the context of the administrator in order to cause worse case impact. This is reflected in the Rockwell CVSS score, as AT:P.

A remote code execution security issue exists in the Rockwell Automation Arena®.  A crafted DOE file can force Arena Simulation to write beyond the boundaries of an allocated object. Exploitation requires user interaction, such as opening a malicious file within the software. If exploited, a threat actor could execute arbitrary code on the target system. The software must run under the context of the administrator in order to cause worse case impact. This is reflected in the Rockwell CVSS score, as AT:P.

EPSS

Процентиль: 7%
0.00028
Низкий

7.1 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-20
CWE-787

Связанные уязвимости

CVSS3: 7.8
nvd
7 месяцев назад

A remote code execution security issue exists in the Rockwell Automation Arena®.  A crafted DOE file can force Arena Simulation to write beyond the boundaries of an allocated object. Exploitation requires user interaction, such as opening a malicious file within the software. If exploited, a threat actor could execute arbitrary code on the target system. The software must run under the context of the administrator in order to cause worse case impact. This is reflected in the Rockwell CVSS score, as AT:P.

CVSS3: 7.8
fstec
7 месяцев назад

Уязвимость программного обеспечения для дискретного моделирования событий и автоматизации Rockwell Automation Arena, связанная с недостаточной проверкой входных данных, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 7%
0.00028
Низкий

7.1 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-20
CWE-787