Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qwg2-xh56-jqw6

Опубликовано: 14 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 7.3

Описание

Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a malicious DOE file.

Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a malicious DOE file.

EPSS

Процентиль: 0%
0.00004
Низкий

7.1 High

CVSS4

7.3 High

CVSS3

Дефекты

CWE-121

Связанные уязвимости

CVSS3: 7.3
nvd
3 месяца назад

Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a malicious DOE file.

CVSS3: 7.3
fstec
3 месяца назад

Уязвимость программного средства для моделирования и автоматизации дискретных событий Rockwell Automation Arena Simulation, связанная с переполнением буфера в стеке, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 0%
0.00004
Низкий

7.1 High

CVSS4

7.3 High

CVSS3

Дефекты

CWE-121