IM
IronMonkey Threat Research
‹ Back to ICS Advisories

Rockwell Automation Arena (Update C)

HIGH
CVSS 7.8
Date 2026-06-23T06:00:00+00:00
Source cisa-csaf
Published by CISA

// Description

Successful exploitation of these vulnerabilities could result in execution of arbitrary code.

// Vulnerabilities (11)

CVE ID CVSS Score Severity Description
CVE-2026-6071 7.5 high
A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.
CVE-2025-6376 7.0 high
A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
CVE-2024-12175 7.8 high
Another "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
CVE-2024-11155 7.8 high
A "use after free" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
CVE-2024-11156 7.8 high
An "out of bounds write" code execution vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
CVE-2024-11364 7.8 high
Another "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
CVE-2024-11157 7.8 high
A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
CVE-2024-12130 7.8 high
An "out of bounds read" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
CVE-2025-6377 7.0 high
A remote code execution security issue exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
CVE-2024-11158 7.8 high
An "uninitialized variable" code execution vulnerability exists in the affected products that could allow a threat actor to craft a DOE file and force the software to access a variable before it is initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
CVE-2024-12672 7.8 high
A third-party vulnerability exists in the affected products that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.

// Remediations (7)

Mitigation: For information on how to mitigate security risks on industrial automation control systems, Rockwell
For information on how to mitigate security risks on industrial automation control systems, Rockwell Automation encourages users to implement their suggested security best practices (login required) to minimize the risk of the vulnerability.
Mitigation: Rockwell Automation encourages users of the affected software to apply the following risk mitigation
Rockwell Automation encourages users of the affected software to apply the following risk mitigations, if possible.
Mitigation: Hold the control key down when loading files to help prevent the VBA file stream from loading.
Hold the control key down when loading files to help prevent the VBA file stream from loading.
Patch: Do not load untrusted Arena model files.
Do not load untrusted Arena model files.
Mitigation: Rockwell Automation recommends users upgrade to V16.20.09 or later.
Rockwell Automation recommends users upgrade to V16.20.09 or later.
Mitigation: Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific
Stakeholder-Specific Vulnerability Categorization can be used to generate more environment-specific prioritization.
Mitigation: For more information about these issues, please see the Rockwell Automation security advisory.
For more information about these issues, please see the Rockwell Automation security advisory.

// References