Vulnerabilities > Rockwellautomation > Arena

DATE CVE VULNERABILITY TITLE RISK
2023-05-09 CVE-2023-29460 Out-of-bounds Read vulnerability in Rockwellautomation Arena 16.00.00/16.20.00
An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffer overflow potentially resulting in a complete loss of confidentiality, integrity, and availability.
network
low complexity
rockwellautomation CWE-125
critical
9.8
2023-05-09 CVE-2023-29461 Out-of-bounds Read vulnerability in Rockwellautomation Arena 16.00.00/16.20.00
An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffer overflow in the heap.
network
low complexity
rockwellautomation CWE-125
critical
9.8
2023-05-09 CVE-2023-29462 Out-of-bounds Write vulnerability in Rockwellautomation Arena 16.00.00/16.20.01
An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffer overflow in the heap.
network
low complexity
rockwellautomation CWE-787
8.8
2020-01-27 CVE-2019-13521 Unspecified vulnerability in Rockwellautomation Arena
A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may result in the limited exposure of information related to the targeted workstation.
local
low complexity
rockwellautomation
7.8
2020-01-27 CVE-2019-13519 Type Confusion vulnerability in Rockwellautomation Arena
A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may result in the limited exposure of information related to the targeted workstation.
local
low complexity
rockwellautomation CWE-843
7.8
2019-09-24 CVE-2019-13527 Access of Uninitialized Pointer vulnerability in Rockwellautomation Arena
In Rockwell Automation Arena Simulation Software Cat.
local
low complexity
rockwellautomation CWE-824
7.8
2019-08-15 CVE-2019-13511 Use After Free vulnerability in Rockwellautomation Arena
Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION EXPOSURE CWE-200.
local
low complexity
rockwellautomation CWE-416
3.3
2019-08-15 CVE-2019-13510 Use After Free vulnerability in Rockwellautomation Arena
Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416.
local
low complexity
rockwellautomation CWE-416
7.8
2018-05-14 CVE-2018-8843 Use After Free vulnerability in Rockwellautomation Arena
Rockwell Automation Arena versions 15.10.00 and prior contains a use after free vulnerability caused by processing specially crafted Arena Simulation Software files that may cause the software application to crash, potentially losing any unsaved data..
local
low complexity
rockwellautomation CWE-416
5.5