ZDI-24-1654: Rockwell Automation Arena Simulation DOE File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Rockwell Automation Arena Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-11156.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1654?
The vulnerability ZDI-24-1654 is considered to have a high severity due to its potential for remote code execution.
How do I fix ZDI-24-1654?
To fix ZDI-24-1654, ensure that you apply the latest security updates from Rockwell Automation for Arena Simulation.
Who is affected by ZDI-24-1654?
ZDI-24-1654 affects installations of Rockwell Automation Arena Simulation that are not updated with the latest patches.
What are the consequences of exploiting ZDI-24-1654?
Exploitation of ZDI-24-1654 can allow remote attackers to execute arbitrary code, potentially leading to data theft or system compromise.
Is user interaction required to exploit ZDI-24-1654?
Yes, user interaction is required for exploiting ZDI-24-1654, as the target must visit a malicious page or open a malicious file.