Vulnerability Description
Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. A maliciously crafted Arena file opened by an unsuspecting user may result in the application crashing or the execution of arbitrary code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Arena | <= 16.00.00 |
Related Weaknesses (CWE)
References
- https://www.us-cert.gov/ics/advisories/icsa-19-213-05MitigationThird Party AdvisoryUS Government Resource
- https://www.zerodayinitiative.com/advisories/ZDI-19-1000/
- https://www.zerodayinitiative.com/advisories/ZDI-19-800/
- https://www.zerodayinitiative.com/advisories/ZDI-19-801/
- https://www.zerodayinitiative.com/advisories/ZDI-19-994/
- https://www.zerodayinitiative.com/advisories/ZDI-19-998/
- https://www.zerodayinitiative.com/advisories/ZDI-19-999/
- https://www.zerodayinitiative.com/advisories/ZDI-20-926/
- https://www.zerodayinitiative.com/advisories/ZDI-20-927/
- https://www.zerodayinitiative.com/advisories/ZDI-20-928/
- https://www.zerodayinitiative.com/advisories/ZDI-20-929/
- https://www.zerodayinitiative.com/advisories/ZDI-20-930/
- https://www.zerodayinitiative.com/advisories/ZDI-20-931/
- https://www.us-cert.gov/ics/advisories/icsa-19-213-05MitigationThird Party AdvisoryUS Government Resource
- https://www.zerodayinitiative.com/advisories/ZDI-19-1000/
FAQ
What is CVE-2019-13510?
CVE-2019-13510 is a vulnerability with a CVSS score of 7.8 (HIGH). Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. A maliciously crafted Arena file opened by an unsuspecting user may result in the applicat...
How severe is CVE-2019-13510?
CVE-2019-13510 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-13510?
Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Arena.