news.mlab.sh
Back to the feed
vulnerability

Rockwell Automation Arena

High
Summary

Rockwell Automation has released an advisory regarding critical vulnerabilities in its Arena simulation software. Specifically, versions up to V17.00.00 are affected by memory corruption flaws that could allow an attacker to execute arbitrary code. Rockwell recommends updating to V17.00.01 to mitigate these risks.

Rockwell Automation has issued a security advisory concerning critical vulnerabilities within its Arena simulation software. These vulnerabilities, identified as memory corruption flaws, could be exploited to allow an attacker to execute arbitrary code within the current process. The affected product is Rockwell Automation Arena, with versions up to V17.00.00. The vulnerabilities stem from improper validation of user-supplied data, leading to out-of-bounds writes. CISA recommends that organizations immediately update to version V17.00.01 to address these security concerns. The advisory highlights the importance of minimizing network exposure for control system devices and isolating them from business networks. CISA also recommends implementing defensive measures such as using VPNs securely and proactively performing impact analysis and risk assessments. No public exploitation specifically targeting these vulnerabilities has been reported at the time of this advisory.

Read the full article at CISA Advisories