Home
HIGH: 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
Version 16.20.10 and prior
affected
Description
Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a malicious DOE file.
Problem types
CWE-121: Stack-based Buffer Overflow
Product status
Version 16.20.10 and prior
References
www.rockwellautomation.com/...dvisories/advisory.SD1763.html