CVE-2025-11918: Rockwell Automation Arena® Simulation Stack-Based Buffer Overflow Vulnerability
Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a malicious DOE file.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-11918?
CVE-2025-11918 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-11918?
To mitigate CVE-2025-11918, users should apply the latest security patches provided by Rockwell Automation.
Who is affected by CVE-2025-11918?
CVE-2025-11918 affects installations of Rockwell Automation Arena that handle DOE file parsing.
What type of vulnerability is CVE-2025-11918?
CVE-2025-11918 is a stack-based buffer overflow vulnerability.
Can CVE-2025-11918 be exploited remotely?
Yes, CVE-2025-11918 can be exploited locally, allowing attackers to execute arbitrary code.