#VU76066 Buffer overflow in Arena Simulation Software - CVE-2023-29460
Published: May 12, 2023 / Updated: December 21, 2023
Arena Simulation Software
Rockwell Automation
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when parsing DOE files. A remote attacker can trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Remediation
External links
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1139391
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-131-10
- https://www.zerodayinitiative.com/advisories/ZDI-23-610/
- https://www.zerodayinitiative.com/advisories/ZDI-23-1899/
- https://www.zerodayinitiative.com/advisories/ZDI-23-1898/