PT-2019-13377 · Rockwell Automation · Arena Simulation

Kimiya

·

Published

2019-08-08

·

Updated

2024-12-17

·

CVE-2019-13511

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier
Description The issue allows for limited exposure of information related to the targeted workstation when a maliciously crafted Arena file is opened by an unsuspecting user. This occurs due to an information exposure weakness.
Recommendations For versions 16.00.00 and earlier, update to a version later than 16.00.00 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2019-13511
ZDI-19-695
ZDI-20-810
ZDI-20-811
ZDI-20-812
ZDI-20-813
ZDI-20-814

Affected Products

Arena Simulation