Impact
A memory corruption flaw in the model.exe component of Arena® Simulation arises from improper validation of user‑supplied data. The flaw enables an out‑of‑bounds write, which an attacker can leverage to execute arbitrary code within the context of the running process. This falls under CWE‑787 and provides a pathway for remote code execution when a user opens a malicious file.
Affected Systems
Rockwell Automation Arena® Simulation is affected. The advisory indicates that versions earlier than V17.00.01 are vulnerable, while upgrading to V17.00.01 or later resolves the issue. No finer‑grained affected build information is provided.
Risk and Exploitability
The CVSS score of 7 indicates moderate to high risk, whereas the EPSS score of <1% suggests a low probability of exploitation at present. The flaw is not listed in CISA KEV. Attack execution requires a local user to open a crafted file while the Arena Simulation process is running, so user interaction is a prerequisite. Given the moderate severity, low exploitation likelihood, and user‑interaction basis, remediation should focus on patching the vulnerable product and strengthening user awareness.
OpenCVE Enrichment