CVE-2024-11156: Rockwell Automation Arena® Out of Bounds Write Vulnerability
An “out of bounds write” code execution vulnerability exists in the
Rockwell Automation Arena®
that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-11156?
CVE-2024-11156 is considered a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2024-11156?
To address CVE-2024-11156, users should update Rockwell Automation Arena to version 16.20.04 or later.
What type of vulnerability is CVE-2024-11156?
CVE-2024-11156 is an out of bounds write vulnerability.
Which versions of Rockwell Automation Arena are affected by CVE-2024-11156?
CVE-2024-11156 affects Rockwell Automation Arena versions up to and including 16.20.03.
How can CVE-2024-11156 be exploited?
CVE-2024-11156 can be exploited by a threat actor to execute arbitrary code through a specially crafted DOE file.