VulnerabilityAnalyzed
CVE-2025-11918
Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability.
HIGH 7.1EPSS 0.16%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.16%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a malicious DOE file.
- CVSS 4.0
- 7.1 HIGHCVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.16% probability · 5th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-121
- Affected
- rockwellautomation/arena
- Source
- PSIRT@rockwellautomation.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.