CVE-2025-3289: Local Code Execution Vulnerability in Arena®
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3289?
CVE-2025-3289 is classified as a local code execution vulnerability with a high severity rating.
How do I fix CVE-2025-3289?
To fix CVE-2025-3289, users should apply the latest security updates provided by Rockwell Automation for Arena®.
What are the potential impacts of CVE-2025-3289?
CVE-2025-3289 could allow a threat actor to execute arbitrary code and disclose sensitive information on affected systems.
Which software is affected by CVE-2025-3289?
CVE-2025-3289 affects Rockwell Automation Arena® software due to a stack-based memory buffer overflow.
How is CVE-2025-3289 exploited?
CVE-2025-3289 can be exploited by supplying improperly validated data that leads to a buffer overflow vulnerability.