Vulnerabilities > CVE-2019-13527 - Access of Uninitialized Pointer vulnerability in Rockwellautomation Arena Simulation Software 16.00.00

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
rockwellautomation
CWE-824

Summary

In Rockwell Automation Arena Simulation Software Cat. 9502-Ax, Versions 16.00.00 and earlier, a maliciously crafted Arena file opened by an unsuspecting user may result in the use of a pointer that has not been initialized.

Common Weakness Enumeration (CWE)