CVE-2025-6376

HIGH

Rockwell Automation Arena < 16.20.09 - Remote Code Execution via Crafted DOE File

Title source: llm
STIX 2.1

Description

A remote code execution security issue exists in the Rockwell Automation Arena®.  A crafted DOE file can force Arena Simulation to write beyond the boundaries of an allocated object. Exploitation requires user interaction, such as opening a malicious file within the software. If exploited, a threat actor could execute arbitrary code on the target system. The software must run under the context of the administrator in order to cause worse case impact. This is reflected in the Rockwell CVSS score, as AT:P.

Scores

CVSS v3 7.8
EPSS 0.0008
EPSS Percentile 23.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-20 CWE-787
Status published
Products (1)
rockwellautomation/arena < 16.20.09
Published Jul 09, 2025
Tracked Since Feb 18, 2026