Impact
A vulnerability in Rockwell Automation Arena allows a remote attacker to execute arbitrary code when the application parses a malicious DOE file or loads a page that forces the parser to handle such a file. The flaw is an out-of-bounds write that writes past the end of an allocated object, permitting an attacker to place and run code in the context of the current Arena process. This results in a loss of confidentiality and integrity critical to the system and can be leveraged by a user who opens a malicious file or visits a malicious page.
Affected Systems
All versions of Rockwell Automation Arena up to and including 16.20.08 are affected. The issue is present in all affected releases regardless of configuration as the vulnerability is triggered during the parsing of DOE files.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate to high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited or no current exploitation. The vulnerability can be triggered by a legitimate user who opens a malicious DOE file or visits a malicious web page, meaning the attack depends on user interaction or social engineering. The exploitation path involves delivering or hosting a malicious DOE file that triggers the out-of-bounds write, after which the attacker can execute code with the privileges of the Arena process.
OpenCVE Enrichment