Rockwell Automation Arena® Simulation Uninitialized Pointer Vulnerability
Vulnerability Description
Rockwell Automation Arena Simulation contains an arbitrary code execution vulnerability that could potentially allow a malicious user to commit unauthorized code to the software by using an uninitialized pointer in the application. The threat-actor could then execute malicious code on the system affecting the confidentiality, integrity, and availability of the product. The user would need to open a malicious file provided to them by the attacker for the code to execute.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-27858
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- These vulnerabilities were reported to Rockwell Automation by Michael Heinzl
More from Rockwell Automation
View All →Affected Vendor
Rockwell Automation
View all reports →