PT-2019-13376 · Rockwell Automation · Arena Simulation

·

CVE-2019-13510

·

Published

2019-08-08

·

Updated

2024-12-17

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier
Description The issue is related to a USE AFTER FREE condition, which can be triggered by opening a maliciously crafted Arena file. This may cause the application to crash or execute arbitrary code.
Recommendations For versions 16.00.00 and earlier, update to a version later than 16.00.00 to resolve the issue. As a temporary workaround, consider avoiding the use of DOE files from untrusted sources until a patch is available. Restrict access to the Arena Simulation Software to minimize the risk of exploitation.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12447
CVE-2019-13510
ZDI-19-1000
ZDI-19-692
ZDI-19-693
ZDI-19-694
ZDI-19-696
ZDI-19-697
ZDI-19-698
ZDI-19-699
ZDI-19-800
ZDI-19-801
ZDI-19-994
ZDI-19-998
ZDI-19-999
ZDI-20-926
ZDI-20-927
ZDI-20-928
ZDI-20-929
ZDI-20-930
ZDI-20-931

Affected Products

Arena Simulation