Impact
The vulnerability is a memory corruption flaw in the Siman component of Rockwell Automation Arena Simulation. Improper validation of user-supplied data allows an out-of-bounds write that can be leveraged to execute arbitrary code in the context of the current user process. The flaw matches CWE‑787, a buffer‑overflow type weakness. Attacker leverage requires convincing a user to open a malicious file, after which code runs with the same privileges as that user.
Affected Systems
Rockwell Automation Arena Simulation, specifically the siman.exe executable, is affected. All versions older than V17.00.01 contain the flaw. The vendor recommends upgrading to V17.00.01 or later to eliminate the issue. No other product versions are listed, and model or release details beyond that version are not specified.
Risk and Exploitability
The vulnerability scores a CVSS v3 of 7, indicating moderate‑to‑high severity. Its EPSS score is listed as less than 1%, suggesting a low likelihood of exploitation in the wild. The vulnerability is not present in the CISA KEV catalog. Exploitation requires the victim to open a specially crafted file; therefore the risk is tied to the exposure of untrusted files to the application.
OpenCVE Enrichment