Vulnerabilities > Rockwellautomation > Arena > 3.00.00

DATE CVE VULNERABILITY TITLE RISK
2024-12-19 CVE-2024-11157 Out-of-bounds Write vulnerability in Rockwellautomation Arena
A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file.
local
low complexity
rockwellautomation CWE-787
7.3
2024-12-19 CVE-2024-12175 Use After Free vulnerability in Rockwellautomation Arena
Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used.
local
low complexity
rockwellautomation CWE-416
7.8
2024-12-05 CVE-2024-11156 Out-of-bounds Write vulnerability in Rockwellautomation Arena
An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file.
local
low complexity
rockwellautomation CWE-787
7.8
2024-12-05 CVE-2024-12130 Out-of-bounds Read vulnerability in Rockwellautomation Arena
An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory.
local
low complexity
rockwellautomation CWE-125
7.8
2023-10-27 CVE-2023-27854 Out-of-bounds Read vulnerability in Rockwellautomation Arena
An arbitrary code execution vulnerability was reported to Rockwell Automation in Arena Simulation that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffer overflow.
local
low complexity
rockwellautomation CWE-125
7.8
2023-10-27 CVE-2023-27858 Access of Uninitialized Pointer vulnerability in Rockwellautomation Arena
Rockwell Automation Arena Simulation contains an arbitrary code execution vulnerability that could potentially allow a malicious user to commit unauthorized code to the software by using an uninitialized pointer in the application.
local
low complexity
rockwellautomation CWE-824
7.8
2018-05-14 CVE-2018-8843 Use After Free vulnerability in Rockwellautomation Arena
Rockwell Automation Arena versions 15.10.00 and prior contains a use after free vulnerability caused by processing specially crafted Arena Simulation Software files that may cause the software application to crash, potentially losing any unsaved data..
local
low complexity
rockwellautomation CWE-416
5.5