cbcvebase.
CVE-2024-21920
published 2024-03-26

CVE-2024-21920: A memory buffer vulnerability in Rockwell Automation Arena Simulation could potentially let a threat actor read beyond the intended memory boundaries. This…

PriorityP425high7.1CVSS 3.1
AVLACLPRNUIRSUCHINAH
EPSS
0.22%
12.4th percentile
A memory buffer vulnerability in Rockwell Automation Arena Simulation could potentially let a threat actor read beyond the intended memory boundaries. This could reveal sensitive information and even cause the application to crash, resulting in a denial-of-service condition. To trigger this, the user would unwittingly need to open a malicious file shared by the threat actor.

Affected

2 ranges
VendorProductVersion rangeFixed in
rockwell_automationarena_simulation
rockwellautomationarena>= 16.00.00
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.