Vulnerability Description
A memory buffer vulnerability in Rockwell Automation Arena Simulation could potentially let a threat actor read beyond the intended memory boundaries. This could reveal sensitive information and even cause the application to crash, resulting in a denial-of-service condition. To trigger this, the user would unwittingly need to open a malicious file shared by the threat actor.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Arena | >= 16.00.00 |
Related Weaknesses (CWE)
References
- https://www.rockwellautomation.com/en-us/support/advisory.SD-1665.htmlBroken Link
- https://www.rockwellautomation.com/en-us/support/advisory.SD-1665.htmlBroken Link
FAQ
What is CVE-2024-21920?
CVE-2024-21920 is a vulnerability with a CVSS score of 4.4 (MEDIUM). A memory buffer vulnerability in Rockwell Automation Arena Simulation could potentially let a threat actor read beyond the intended memory boundaries. This could reveal sensitive information and ev...
How severe is CVE-2024-21920?
CVE-2024-21920 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-21920?
Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Arena.