CVE Database
/

CVE-2025-3286

Back to search

CVE-2025-3286

Published: Apr 8, 2025

Modified: Apr 8, 2025

PUBLISHED

Description

A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data.  If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user must open a malicious DOE file.

VendorProductVersions

Rockwell Automation

Arena®

affected
16.20.08 and earlier

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now