CVE-2026-8085: Rockwell Automation Arena® - Memory Corruption Vulnerability
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Arena® Simulation (model.exe Siman)to a version that resolves this vulnerability.Fixed in 17.00.01
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8085?
The severity of CVE-2026-8085 is rated as high with a score of 7 on the CVSS scale.
What is the primary issue of CVE-2026-8085?
CVE-2026-8085 is a memory corruption vulnerability found in the model.exe component of Rockwell Automation Arena® Simulation.
How can an attacker exploit CVE-2026-8085?
An attacker can exploit CVE-2026-8085 by supplying malformed data that leads to an out-of-bounds write, potentially allowing for arbitrary code execution.
How do I fix CVE-2026-8085?
To fix CVE-2026-8085, ensure that the latest security patch from Rockwell Automation is applied, which addresses the memory corruption issue.
What versions of Rockwell Automation Arena® are affected by CVE-2026-8085?
CVE-2026-8085 affects specific versions of Rockwell Automation Arena® Simulation but details on affected versions are typically provided in the associated security advisory.