CVE-2025-7025

A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a bad file or webpage. If used, a threat actor could execute code or disclose information.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rockwellautomation:arena:*:*:*:*:*:*:*:*

History

07 Aug 2025, 14:31

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1731.html - () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1731.html - Vendor Advisory
Summary
  • (es) Existe un problema de abuso de memoria en Rockwell Automation Arena® Simulation. Un archivo personalizado puede obligar a Arena Simulation a leer y escribir más allá del límite de memoria. Para usarlo correctamente, se requiere la intervención del usuario, como abrir un archivo o una página web maliciosos. De ser utilizado, un atacante podría ejecutar código o divulgar información.
CPE cpe:2.3:a:rockwellautomation:arena:*:*:*:*:*:*:*:*
First Time Rockwellautomation arena
Rockwellautomation

05 Aug 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-05 14:15

Updated : 2025-08-07 14:31


NVD link : CVE-2025-7025

Mitre link : CVE-2025-7025

CVE.ORG link : CVE-2025-7025


JSON object : View

Products Affected

rockwellautomation

  • arena
CWE
CWE-122

Heap-based Buffer Overflow