Uninitialized Pointer Vulnerability in Rockwell Automation Arena Simulation Software Could Lead to Code Injection
CVE-2024-21919
7.8HIGH
Summary
An uninitialized pointer vulnerability exists in Rockwell Automation's Arena Simulation Software, which could permit unauthorized code insertion by exploiting the pointer during specific user interactions. A malicious actor may craft a harmful file that, when opened by a user, allows for execution of detrimental code within the system. This vulnerability poses substantial risks to the confidentiality, integrity, and availability of the software, underscoring the necessity for users to remain cautious about opening unsolicited files and for vendors to address such security flaws promptly.
Affected Version(s)
Arena Simulation Version 16.00 - 16.20.02
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michael Heinzl