CVE-2024-12130: Rockwell Automation Arena® Out of Bounds Read Vulnerability
An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena®
that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12130?
CVE-2024-12130 is classified as a critical severity vulnerability due to its potential to allow code execution via an out of bounds read.
How do I fix CVE-2024-12130?
To remediate CVE-2024-12130, users should update Rockwell Automation Arena software to a version that addresses the vulnerability.
Who is affected by CVE-2024-12130?
CVE-2024-12130 affects users of Rockwell Automation Arena versions up to and including 16.20.03.
What exploit is associated with CVE-2024-12130?
CVE-2024-12130 can be exploited by a threat actor crafting a specially designed DOE file that causes the software to read beyond allocated memory boundaries.
What are the potential impacts of CVE-2024-12130?
Exploitation of CVE-2024-12130 could lead to unauthorized code execution, resulting in a compromise of system integrity and potential data breach.