CVE-2024-11158
MEDIUMDescription
An “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable before it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
Is your site exposed to CVE-2024-11158?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| rockwellautomation | arena |
References
Frequently Asked Questions
What is CVE-2024-11158? +
How severe is CVE-2024-11158? +
What products are affected by CVE-2024-11158? +
How do I check if I'm vulnerable to CVE-2024-11158? +
Related Vulnerabilities
Improper initialization in the UEFI firmware for some Intel platforms within Ring 0: Bare Metal OS may allow an information …
The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A vulnerability exists in the version …
An improper input validation allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by sending …
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, …
The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via …
Memory corruptions can be remotely triggered in the Control-M/Agent when SSL/TLS communication is configured. The issue occurs in the following …