CVE-2024-21920

A memory buffer vulnerability in Rockwell Automation Arena Simulation could potentially let a threat actor read beyond the intended memory boundaries. This could reveal sensitive information and even cause the application to crash, resulting in a denial-of-service condition. To trigger this, the user would unwittingly need to open a malicious file shared by the threat actor.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rockwellautomation:arena_simulation:*:*:*:*:*:*:*:*

History

09 Dec 2024, 15:25

Type Values Removed Values Added
References () https://www.rockwellautomation.com/en-us/support/advisory.SD-1665.html - () https://www.rockwellautomation.com/en-us/support/advisory.SD-1665.html - Broken Link
First Time Rockwellautomation
Rockwellautomation arena Simulation
CPE cpe:2.3:a:rockwellautomation:arena_simulation:*:*:*:*:*:*:*:*

21 Nov 2024, 08:55

Type Values Removed Values Added
References () https://www.rockwellautomation.com/en-us/support/advisory.SD-1665.html - () https://www.rockwellautomation.com/en-us/support/advisory.SD-1665.html -
Summary
  • (es) Una vulnerabilidad del búfer de memoria en Rockwell Automation Arena Simulation podría permitir que un actor de amenazas lea más allá de los límites de memoria previstos. Esto podría revelar información confidencial e incluso provocar que la aplicación falle, lo que provocaría una condición de denegación de servicio. Para desencadenar esto, el usuario tendría que abrir, sin saberlo, un archivo malicioso compartido por el actor de la amenaza.

26 Mar 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-03-26 16:15

Updated : 2024-12-09 15:25


NVD link : CVE-2024-21920

Mitre link : CVE-2024-21920

CVE.ORG link : CVE-2024-21920


JSON object : View

Products Affected

rockwellautomation

  • arena_simulation
CWE
CWE-125

Out-of-bounds Read