Uninitialized Pointer Vulnerability in Rockwell Automation Arena Simulation Software Could Lead to Code Injection
CVE-2024-21919

7.8HIGH

Key Information:

Vendor
CVE Published:
26 March 2024

Summary

An uninitialized pointer vulnerability exists in Rockwell Automation's Arena Simulation Software, which could permit unauthorized code insertion by exploiting the pointer during specific user interactions. A malicious actor may craft a harmful file that, when opened by a user, allows for execution of detrimental code within the system. This vulnerability poses substantial risks to the confidentiality, integrity, and availability of the software, underscoring the necessity for users to remain cautious about opening unsolicited files and for vendors to address such security flaws promptly.

Affected Version(s)

Arena Simulation Version 16.00 - 16.20.02

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl
.