Remote Code Execution Vulnerability in Rockwell Automation Arena®
CVE-2025-6376

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
9 July 2025

What is CVE-2025-6376?

A security issue in Rockwell Automation's Arena® Simulation Software allows for remote code execution through crafted DOE files. When a user opens a malicious DOE file, it could lead to writing beyond an allocated object's boundary. This vulnerability necessitates user interaction, including executing the malicious file. If exploited successfully with administrative privileges, it enables threat actors to run arbitrary code on the target system, posing a significant risk to data integrity and system security.

Affected Version(s)

Arena® <=16.20.08

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6376 : Remote Code Execution Vulnerability in Rockwell Automation Arena®