Memory Buffer Vulnerability Threatens Confidentiality, Integrity, and Availability of Arena Simulation Software
CVE-2024-21918

7.8HIGH

Key Information:

Vendor
CVE Published:
26 March 2024

Summary

A memory buffer vulnerability exists in Rockwell Automation’s Arena Simulation software, potentially allowing a malicious user to insert unauthorized code through memory corruption. By exploiting this weakness, a threat actor could trigger an access violation upon the user opening a compromised file, leading to harmful code execution on the affected system. This vulnerability jeopardizes the confidentiality, integrity, and availability of critical data and system functions, posing significant risks to users who interact with the software.

Affected Version(s)

Arena Simulation Version 16.00 - 16.20.02

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl
.