ZeroHour

CVE-2026-6071

moderate

Out-of-bounds write RCE in Rockwell Automation Arena via malicious DOE files

CVSS 4.0
7.5 high
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-6071 is an out-of-bounds write (CWE-787) in Rockwell Automation's affected products — most plausibly the Arena simulation software, whose native model format is the DOE file named in the advisory — that occurs when parsing DOE files and allows an attacker to write past the end of an allocated object and execute code in the context of the current process. Exploitation requires user interaction: a legitimate user must open a malicious DOE file or visit a malicious page, which is reflected in the CVSS 4.0 score of 7.5 (High) with network attack vector, high attack complexity, a prerequisite attack condition, and active user interaction. An attacker who succeeds gains arbitrary code execution with the privileges of the user running the software. Users running affected versions are affected; the exact affected version ranges are not enumerated in the available data and must be confirmed in the Rockwell Automation advisory. Exploitation status is currently quiet: no public proof-of-concept is known, the flaw is not in the CISA KEV catalog, and EPSS assigns a 0.4% probability of exploitation in the next 30 days (37th percentile).

What to do: Check installed Arena versions against the Rockwell Automation security advisory and upgrade to a fixed release as soon as one is published. Until then, do not open DOE files from untrusted or unexpected sources (email attachments, downloads, shared drives) and treat DOE files delivered via web pages as untrusted. Because exploitation depends on user action, brief everyone who uses Arena on the risk of opening untrusted model files and watch for unexpected Arena process crashes or child-process spawns.

Affected
Rockwell Automation Arena simulation software (parses DOE model files)
Estimated exposure
moderate≈ tens of thousands of installed seats worldwide (estimate; no public install counts) — Arena is a long-established, specialized discrete-event simulation desktop application used in manufacturing, engineering services, and academia, suggesting a global installed base plausibly in the 10k–100k seat range, and only users who…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution security issue exists in the affected products when parsing DOE files that could allow a remote attacker to write past the end of an allocated object and execute code within the context of the current process. To exploit this vulnerability, a legitimate user must visit a malicious page or open a malicious file.

Weakness
CWE-787
Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.