Rockwell Automation Arena® Simulation是美国Rockwell Automation基金会的一个自动化控制模拟软件。 Rockwell Automation Arena® Simulation V17.00.00及之前版本存在缓冲区错误漏洞,该漏洞源于siman.exe(Siman)组件存在内存损坏,由于对用户提供的数据验证不当,可能导致越界写入,攻击者通过说服用户打开恶意文件,可在当前进程环境中执行任意代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Rockwell Automation | Arena® Simulation | V17.00.00 and prior |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Rockwell Automation | Arena® Simulation | V17.00.00 and prior | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-12011 | 9.2 CRITICAL | CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow |
| CVE-2026-10573 | 6.3 MEDIUM | 1734 POINT I/OTM - Denial of Service via Malformed Inputs on CIP Object |
| CVE-2026-8085 | Rockwell Automation Arena® - Memory Corruption Vulnerability | |
| CVE-2026-8313 | Rockwell Automation Arena® - Memory Corruption Vulnerability | |
| CVE-2026-9653 | 1756-EN2, 1756-EN3, and 1756-ENBT - Denial of Service via CIP Connection ID | |
| CVE-2026-9140 | 1718-AENTR/1719-AENTR - Denial of Service | |
| CVE-2026-10714 | Rockwell Automation FactoryTalk® Services Platform FTSP - Weak Authentication via JWT Vali | |
| CVE-2025-12012 | CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow | |
| CVE-2026-11917 | ThinManager® - Path Traversal via API | |
| CVE-2026-9108 | Studio 5000 Logix Designer® – Multiple Vulnerabilities | |
| CVE-2026-9128 | Studio 5000 Logix Designer® – Multiple Vulnerabilities | |
| CVE-2026-9636 | Rockwell Automation CompactLogix® 5380 ControlLogix® 5580 / 1756-EN4 Communications Module | |
| CVE-2026-9292 | Rockwell Automation FactoryTalk® DataMosaix™ Private Cloud - Stored Cross-Site Scripting | |
| CVE-2026-9127 | Studio 5000 Logix Designer® – Multiple Vulnerabilities | |
| CVE-2026-12659 | Rockwell Automation Flex 5000® Adapter - Denial of Service | |
| CVE-2025-11698 | CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow |
No comments yet