Rockwellautomation
Rockwellautomation Arena: vulnerabilidades y CVE
Rockwellautomation Arena tiene 46 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE46
Últimos 12 meses5
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-8314 | Alta (7) | 0.27% | — | 14 jul 2026 | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in… |
| CVE-2026-8313 | Alta (7) | 0.27% | — | 14 jul 2026 | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in… |
| CVE-2026-8312 | Alta (7) | 0.27% | — | 14 jul 2026 | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in… |
| CVE-2026-8085 | Alta (7) | 0.27% | — | 14 jul 2026 | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in… |
| CVE-2025-11918 | Alta (7.1) | 0.16% | — | 14 nov 2025 | Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute… |
| CVE-2025-7033 | Alta (8.4) | 0.26% | — | 5 ago 2025 | A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a… |
| CVE-2025-7032 | Alta (8.4) | 0.26% | — | 5 ago 2025 | A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a… |
| CVE-2025-7025 | Alta (8.4) | 0.26% | — | 5 ago 2025 | A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a… |
| CVE-2025-6377 | Alta (7.1) | 0.22% | — | 9 jul 2025 | A remote code execution security issue exists in the Rockwell Automation Arena®. A crafted DOE file can force Arena Simulation to write beyond the boundaries of an allocated object. Exploitation requires user… |
| CVE-2025-6376 | Alta (7.1) | 0.22% | — | 9 jul 2025 | A remote code execution security issue exists in the Rockwell Automation Arena®. A crafted DOE file can force Arena Simulation to write beyond the boundaries of an allocated object. Exploitation requires user… |
| CVE-2025-3289 | Alta (8.5) | 0.31% | — | 8 abr 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can… |
| CVE-2025-3288 | Alta (8.5) | 0.30% | — | 8 abr 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied… |
| CVE-2025-3287 | Alta (8.5) | 0.31% | — | 8 abr 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can… |
| CVE-2025-3286 | Alta (8.5) | 0.30% | — | 8 abr 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied… |
| CVE-2025-3285 | Alta (8.5) | 0.30% | — | 8 abr 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied… |
| CVE-2025-2829 | Alta (8.5) | 0.30% | — | 8 abr 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of… |
| CVE-2025-2293 | Alta (8.5) | 0.30% | — | 8 abr 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of… |
| CVE-2025-2288 | Alta (8.5) | 0.30% | — | 8 abr 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of… |
| CVE-2025-2287 | Alta (8.5) | 0.30% | — | 8 abr 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose… |
| CVE-2025-2286 | Alta (8.5) | 0.30% | — | 8 abr 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose… |
| CVE-2025-2285 | Alta (8.5) | 0.30% | — | 8 abr 2025 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose… |
| CVE-2024-12672 | Alta (8.5) | 0.22% | — | 19 dic 2024 | A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this… |
| CVE-2024-12175 | Alta (8.5) | 0.25% | — | 19 dic 2024 | Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If… |
| CVE-2024-11364 | Alta (8.5) | 0.34% | — | 19 dic 2024 | Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being… |
| CVE-2024-11157 | Alta (8.5) | 0.23% | — | 19 dic 2024 | A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this… |
| CVE-2024-12130 | Alta (8.5) | 0.30% | — | 5 dic 2024 | An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated… |
| CVE-2024-11158 | Alta (8.5) | 0.23% | — | 5 dic 2024 | An “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable before it being… |
| CVE-2024-11156 | Alta (8.5) | 0.24% | — | 5 dic 2024 | An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat… |
| CVE-2024-11155 | Alta (8.5) | 0.23% | — | 5 dic 2024 | A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited,… |
| CVE-2024-2929 | Alta (7.8) | 0.35% | — | 26 mar 2024 | A memory corruption vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code to the software by corrupting the memory triggering an access… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Rockwellautomation
Micrologix 1400 B Firmware · 22Factorytalk View · 18Thinmanager · 17Factorytalk Linx · 14Factorytalk Services Platform · 14Micrologix 1100 Firmware · 14Controllogix 5580 Firmware · 13Guardlogix 5580 Firmware · 13Factorytalk Assetcentre · 12Compactlogix 5380 Firmware · 12Compactlogix 5480 Firmware · 11Micrologix 1400 Firmware · 11