A memory buffer vulnerability in Rockwell Automation Arena Simulation could potentially let a threat actor read beyond the intended memory boundaries. This could reveal sensitive information and even cause the application to crash, resulting in a denial-of-service condition. To trigger this, the user would unwittingly need to open a malicious file shared by the threat actor.
Workaround:
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.rockwellautomation.com/en-us/support/advisory.SD-1665.html | broken link |