CVE-2024-21912
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2024-21912 is a serious vulnerability impacting Rockwell Automation Arena Simulation software. An attacker can exploit this arbitrary code execution flaw by writing beyond the designated memory area, leading to an access violation. This opens the door for unauthorized code injection, potentially allowing the threat actor to run harmful code on the system. The consequences of this vulnerability include risks to the confidentiality, integrity, and availability of the product. Triggering this issue requires the user to open a maliciously crafted file from the attacker.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Rockwell Automation