Exploring Code Execution Vulnerabilities in Rockwell Automation Arena®
CVE-2024-12175
Summary
CVE-2024-12175 is a high-risk vulnerability classified as a 'use after free' code execution flaw affecting Rockwell Automation's Arena® software. This vulnerability allows a threat actor to manipulate the software by crafting a malformed DOE file that exploits a previously released resource. If successfully executed, this could permit the adversary to run arbitrary code within the application environment. To execute this exploit, the victim, typically a legitimate user, must unknowingly run the malicious code provided by the attacker. The implications of this vulnerability can lead to severe security breaches, making it essential for users to apply the latest security patches and remain vigilant against such exploits.
Affected Version(s)
Arena® All versions 16.20.06 and prior
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved