CVE-2024-21912

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 26, 2024
Updated: Dec 17, 2024
CWE ID 787

Summary

CVE-2024-21912 is a serious vulnerability impacting Rockwell Automation Arena Simulation software. An attacker can exploit this arbitrary code execution flaw by writing beyond the designated memory area, leading to an access violation. This opens the door for unauthorized code injection, potentially allowing the threat actor to run harmful code on the system. The consequences of this vulnerability include risks to the confidentiality, integrity, and availability of the product. Triggering this issue requires the user to open a maliciously crafted file from the attacker.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share