PT-2023-8024 · Rockwell Automation · Arena Simulation

Published

2023-05-09

·

Updated

2024-12-17

·

CVE-2023-29460

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Rockwell Automation Arena Simulation (affected versions not specified)
Description The issue is related to an arbitrary code execution vulnerability in Rockwell Automation's Arena Simulation software. This vulnerability could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffer overflow, resulting in a complete loss of confidentiality, integrity, and availability. The vulnerability is also described as a buffer overflow issue that could allow a remote attacker to execute arbitrary code. Additionally, it is mentioned as a use-after-free and out-of-bounds write remote code execution vulnerability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2023-09146
CVE-2023-29460
ZDI-23-1898
ZDI-23-1899
ZDI-23-610

Affected Products

Arena Simulation