Cyber Security News

Rockwell Automation Vulnerabilities Let Attackers Execute Remote Code

Rockwell Automation, a leading provider of industrial automation solutions, has disclosed multiple critical vulnerabilities in its Arena software that could allow attackers to execute remote code.

The company has released security updates to address these high-severity flaws, urging users to upgrade to the latest version immediately.

Four distinct vulnerabilities have been identified in Arena software versions 16.20.03 and prior:

  1. CVE-2024-11155: A “use after free” vulnerability
  2. CVE-2044-11156: An “out of bounds write” vulnerability
  3. CVE-2024-11158: An “uninitialized variable” vulnerability
  4. CVE-2024-12130: An “out of bounds read” vulnerability

All four vulnerabilities have been assigned a CVSS v3.1 base score of 7.8 and a CVSS v4.0 base score of 8.5, indicating their high severity.

Rockwell Automation experts discovered that the vulnerabilities can be exploited by crafting malicious DOE files that manipulate memory allocation and resource usage in the Arena software.

While the attack requires a legitimate user to execute the malicious code, the potential impact is significant.

Free Webinar on Best Practices for API vulnerability & Penetration Testing:  Free Registration

Technical Analysis

If successfully exploited, these vulnerabilities could allow an attacker to:-

  • Execute arbitrary code on the affected system
  • Gain unauthorized access to sensitive information
  • Potentially disrupt industrial operations

Rockwell Automation has released version 16.20.06 of the Arena software, which addresses all four vulnerabilities. Users are strongly advised to upgrade to this version or later to mitigate the risk.

Additionally, the company recommends implementing security best practices for industrial automation control systems to minimize vulnerability risks. These may include:-

  • Restricting network access to critical systems
  • Implementing robust access controls
  • Regularly monitoring systems for suspicious activities
  • Keeping all software and firmware up to date

This disclosure highlights the ongoing cybersecurity challenges faced by the industrial automation sector. As critical infrastructure becomes increasingly connected, the potential impact of such vulnerabilities grows more severe.

Organizations relying on Rockwell Automation’s Arena software should prioritize this update to ensure the security and integrity of their operations.

The vulnerabilities were reported through the Zero Day Initiative (ZDI), underscoring the importance of responsible disclosure and collaboration between security researchers and vendors in identifying and addressing potential threats to industrial systems.

Analyse Real-World Malware & Phishing Attacks With ANY.RUN - Get up to 3 Free Licenses

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Top 10 Best Cloud Detection & Response (CDR) Solutions in 2026

CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…

4 minutes ago

Top 10 Best SaaS Security Posture Management (SSPM) Tools in 2026

Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…

10 minutes ago

Top 10 Best Data Security Posture Management (DSPM) Tools in 2026

DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…

15 minutes ago

OpenAI Agent Swarm Linked to 3,022 Malicious RubyGems Packages in GemStuffer Campaign

Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…

26 minutes ago

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

5 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

15 hours ago