CVE-2025-3285: Local Code Execution Vulnerability in Arena®
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3285?
CVE-2025-3285 has a high severity rating due to its potential for local code execution and information disclosure.
How can I fix CVE-2025-3285?
To mitigate CVE-2025-3285, ensure that you apply the latest security patches provided by Rockwell Automation for Arena.
What causes CVE-2025-3285?
CVE-2025-3285 is caused by improper validation of user-supplied data, allowing access outside of the allocated memory buffer.
Who is affected by CVE-2025-3285?
CVE-2025-3285 affects users of Rockwell Automation Arena software.
What are the potential impacts of CVE-2025-3285?
If exploited, CVE-2025-3285 could lead to unauthorized code execution and disclosure of sensitive information.