Impact
The reported issue is a memory corruption flaw in the expmt.exe (Siman) component of Arena® Simulation. Improper validation of user‑supplied data permits an out‑of‑bounds write, enabling an attacker to execute arbitrary code within the context of the running process. The flaw is classified as CWE‑787.
Affected Systems
Affected vendor is Rockwell Automation and the product is Arena® Simulation. Versions prior to V17.00.01 are vulnerable; upgrading to that release or later removes the flaw.
Risk and Exploitability
The CVSS score of 7 indicates a high‑severity vulnerability, yet the EPSS score of less than 1% shows a very low likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation requires a user to convince someone to open a malicious file that triggers expmt.exe, so social engineering is the most probable attack vector. If exploited, the attacker would run code with the permissions of the user opening the file.
OpenCVE Enrichment