CVE-2025-11918

Severity CVSS v4.0:
HIGH
Type:
CWE-121 Stack-based Buffer Overflow
Publication date:
14/11/2025
Last modified:
14/11/2025

Description

Rockwell Automation Arena® suffers from a<br /> stack-based buffer overflow vulnerability. The specific flaw exists within the<br /> parsing of DOE files. Local attackers are able to exploit this issue to<br /> potentially execute arbitrary code on affected installations of Arena®. Exploiting<br /> the vulnerability requires opening a malicious DOE file.