Rockwell Automation, a leading provider of industrial automation solutions, announced the existence of multiple critical vulnerabilities in its software , which could allow hackers to execute remote code.

The company has already released security updates to address these vulnerabilities, urging users to immediately upgrade to the latest version.
Read more: Microsoft: Discloses Critical Vulnerabilities in Rockwell Automation PanelView Plus
The vulnerabilities that were discovered affect versions 16.20.03 and earlier of the Arena software. Below are the four vulnerabilities, along with their scores:
- CVE-2024-11155: “use after free” vulnerability
- CVE-2024-11156: Out of bounds write vulnerability
- CVE-2024-11158: “uninitialized variable” vulnerability
- CVE-2024-12130: “out of bounds read” vulnerability
These vulnerabilities have been rated with a CVSS v3.1 score of 7.8 and a CVSS v4.0 score of 8.5, underscoring their severity. According to Rockwell Automation, the vulnerabilities can be exploited via malicious DOE files, which disrupt memory and resource management in Arena. While the malicious code requires activation by a legitimate user, the potential impact remains particularly concerning.
If the vulnerabilities are successfully exploited, a hacker can:
- Execute arbitrary code on the affected system.
- To gain unauthorized access to sensitive data.
- To cause a disruption or malfunction in industrial operations.
See also: Flaw in Rockwell Automation devices allows unauthorized access
Rockwell Automation has released version 16.20.06 of the Arena software, which fixes all the above vulnerabilities. Users are advised to upgrade immediately to the latest or any newer version. Additionally, the company recommends using best security practices, such as:
- Restrict network access to critical systems.
- Implement strict access controls.
- Regular monitoring for suspicious activities.
- Update all software and firmware.

The disclosure of these vulnerabilities highlights the ongoing cybersecurity challenges in the industrial automation sector. With critical infrastructure becoming increasingly interconnected, the impact of such vulnerabilities can be far-reaching. Organizations using Arena should prioritize upgrading to protect their operations from potential threats.
Read more: Rockwell Automation tells administrators to disconnect ICS devices
It is worth noting that the vulnerabilities were reported through the Zero Day Initiative (ZDI), highlighting the importance of responsible disclosure and collaboration between security researchers and technology vendors to protect industrial systems from potential attacks.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
