CVE Database
/

CVE-2025-11918

Back to search

CVE-2025-11918

Published: Nov 14, 2025

Modified: Nov 14, 2025

PUBLISHED

Description

Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a malicious DOE file.

VendorProductVersions

Rockwell Automation

Arena® Simulation

affected
Version 16.20.10 and prior

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now