CVE-2025-11918
🟡 Monitoruj
Przepełnienie bufora w Rockwell Automation Arena umożliwia lokalne wykonanie dowolnego kodu.
CVSS
7.3
EPSS
0.2%
Exploit
none
Vendor
rockwellautomation
Opis źródłowy (NVD)
Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a malicious DOE file.
buffer-overflow
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.3 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.2% |
| Opublikowano (NVD) | 2025-11-14 14:15:45 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-07 21:10:00 UTC |
Referencje