CVE Explorer
CVE-2025-6377
A remote
code execution security issue exists in the Rockwell Automation Arena®. A crafted DOE
file can force Arena Simulation to write beyond the boundaries of an allocated
object. Exploitation
requires user interaction, such as opening a malicious file within the software.
If exploited, a threat actor could execute arbitrary code on the target system.
The software must run under the context of the administrator in order to cause
worse case impact. This is reflected in the Rockwell CVSS score,
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Arena®","vendor":"Rockwell Automation","versions":[{"status":"affected","version":"<=16.20.08"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:b55cada4f783bd9035c230d8f17d75788542b217705dd2f42b2760706278c4bc · sha256:32535d8413909e5c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"HIGH","attackRequirements":"PRESENT","attackVector":"LOCAL","baseScore":7.1,"baseSeverity":"HIGH","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"ACTIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:b55cada4f783bd9035c230d8f17d75788542b217705dd2f42b2760706278c4bc · sha256:32535d8413909e5c… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-20","description":"CWE-20 Improper Input Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:b55cada4f783bd9035c230d8f17d75788542b217705dd2f42b2760706278c4bc · sha256:32535d8413909e5c… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1729.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:b55cada4f783bd9035c230d8f17d75788542b217705dd2f42b2760706278c4bc · sha256:32535d8413909e5c… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.