CVE-2024-6068

HIGH

Product - Memory Corruption

Title source: llm
STIX 2.1

Description

A memory corruption vulnerability exists in the affected products when parsing DFT files. Local threat actors can exploit this issue to disclose information and to execute arbitrary code. To exploit this vulnerability a legitimate user must open a malicious DFT file.

Scores

CVSS v3 7.3
EPSS 0.0006
EPSS Percentile 17.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-1284
Status published
Products (1)
Rockwell Automation/Arena Input Analyzer <=16.20.03
Published Nov 14, 2024
Tracked Since Feb 18, 2026