Rockwell Automation Arena Simulation contains an...
High severity
Unreviewed
Published
Oct 27, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Oct 27, 2023
Published to the GitHub Advisory Database
Oct 27, 2023
Last updated
Apr 4, 2024
Rockwell Automation Arena Simulation contains an arbitrary code execution vulnerability that could potentially allow a malicious user to commit unauthorized code to the software by using an uninitialized pointer in the application. The threat-actor could then execute malicious code on the system affecting the confidentiality, integrity, and availability of the product. The user would need to open a malicious file provided to them by the attacker for the code to execute.
References