Rockwell Automation, a leading provider of industrial automation solutions, has disclosed multiple critical vulnerabilities in its Arena software that could allow attackers to execute remote code.
The company has released security updates to address these high-severity flaws, urging users to upgrade to the latest version immediately.
Four distinct vulnerabilities have been identified in Arena software versions 16.20.03 and prior:
All four vulnerabilities have been assigned a CVSS v3.1 base score of 7.8 and a CVSS v4.0 base score of 8.5, indicating their high severity.
Rockwell Automation experts discovered that the vulnerabilities can be exploited by crafting malicious DOE files that manipulate memory allocation and resource usage in the Arena software.
While the attack requires a legitimate user to execute the malicious code, the potential impact is significant.
Free Webinar on Best Practices for API vulnerability & Penetration Testing: Free Registration
If successfully exploited, these vulnerabilities could allow an attacker to:-
Rockwell Automation has released version 16.20.06 of the Arena software, which addresses all four vulnerabilities. Users are strongly advised to upgrade to this version or later to mitigate the risk.
Additionally, the company recommends implementing security best practices for industrial automation control systems to minimize vulnerability risks. These may include:-
This disclosure highlights the ongoing cybersecurity challenges faced by the industrial automation sector. As critical infrastructure becomes increasingly connected, the potential impact of such vulnerabilities grows more severe.
Organizations relying on Rockwell Automation’s Arena software should prioritize this update to ensure the security and integrity of their operations.
The vulnerabilities were reported through the Zero Day Initiative (ZDI), underscoring the importance of responsible disclosure and collaboration between security researchers and vendors in identifying and addressing potential threats to industrial systems.
Analyse Real-World Malware & Phishing Attacks With ANY.RUN - Get up to 3 Free Licenses
CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…
Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…
DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…
Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…