CVE-2025-2285: Local Code Execution Vulnerability in Arena®
A local code execution vulnerability exists in the Rockwell Automation Arena® due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2285?
CVE-2025-2285 has a high severity level due to its potential for local code execution.
How do I fix CVE-2025-2285?
To address CVE-2025-2285, ensure that you apply the latest security patches provided by Rockwell Automation for Arena.
What software is affected by CVE-2025-2285?
CVE-2025-2285 affects the Rockwell Automation Arena software.
What are the consequences of exploiting CVE-2025-2285?
Exploitation of CVE-2025-2285 can lead to arbitrary code execution and potential information disclosure.
Who can exploit CVE-2025-2285?
CVE-2025-2285 can be exploited by attackers with local access to the affected system.