cbcvebase.

Rockwellautomation Arena vulnerabilities

45 known vulnerabilities affecting rockwellautomation/arena.

Total CVEs
45
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH40MEDIUM2LOW1

Vulnerabilities

Page 3 of 3
CVE-2023-27858P3HIGHCVSS 7.8fixed in 16.20.022023-10-27
CVE-2023-27858 [HIGH] CWE-824 CVE-2023-27858: Rockwell Automation Arena Simulation contains an arbitrary code execution vulnerability that could Rockwell Automation Arena Simulation contains an arbitrary code execution vulnerability that could potentially allow a malicious user to commit unauthorized code to the software by using an uninitialized pointer in the application. The threat-actor could then execute malicious code on the system affecting the confidentiality, integrity, and availability
nvd
CVE-2024-11158P3MEDIUMCVSS 6.7≤ 16.20.002024-12-05
CVE-2024-11158 [MEDIUM] CWE-665 CVE-2024-11158: An “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® An “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable before it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legiti
nvd
CVE-2024-21920P4HIGHCVSS 7.1≥ 16.00.002024-03-26
CVE-2024-21920 [HIGH] CWE-125 CVE-2024-21920: A memory buffer vulnerability in Rockwell Automation Arena Simulation could potentially let a thr A memory buffer vulnerability in Rockwell Automation Arena Simulation could potentially let a threat actor read beyond the intended memory boundaries. This could reveal sensitive information and even cause the application to crash, resulting in a denial-of-service condition. To trigger this, the user would unwittingly need to open a malicious file shared
nvd
CVE-2018-8843P4MEDIUMCVSS 5.5≤ 15.10.002018-05-14
CVE-2018-8843 [MEDIUM] CWE-416 CVE-2018-8843: Rockwell Automation Arena versions 15.10.00 and prior contains a use after free vulnerability caused Rockwell Automation Arena versions 15.10.00 and prior contains a use after free vulnerability caused by processing specially crafted Arena Simulation Software files that may cause the software application to crash, potentially losing any unsaved data..
nvd
CVE-2019-13511P4LOWCVSS 3.3≤ 16.00.002019-08-15
CVE-2019-13511 [LOW] CWE-200 CVE-2019-13511: Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION E Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION EXPOSURE CWE-200. A maliciously crafted Arena file opened by an unsuspecting user may result in the limited exposure of information related to the targeted workstation.
nvd
Rockwellautomation Arena vulnerabilities | cvebase