CVE-2024-11155: Rockwell Automation Arena® Use After Free Vulnerability
A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11155?
CVE-2024-11155 is classified as a critical 'use after free' code execution vulnerability.
How do I fix CVE-2024-11155?
To mitigate CVE-2024-11155, users should apply the latest security updates provided by Rockwell Automation for Arena software.
What versions of Rockwell Automation Arena are affected by CVE-2024-11155?
All versions of Rockwell Automation Arena are potentially affected by CVE-2024-11155 if they allow the execution of crafted DOE files.
How can CVE-2024-11155 be exploited?
CVE-2024-11155 can be exploited by crafting a malicious DOE file that forces Arena to use a resource that has already been freed.
Is there a workaround for CVE-2024-11155?
Currently, the best approach for CVE-2024-11155 is to update to a patched version of Arena as no specific workaround is provided.