An “uninitialized variable” code execution vulnerability...
High severity
Unreviewed
Published
Dec 5, 2024
to the GitHub Advisory Database
•
Updated Dec 6, 2024
Description
Published by the National Vulnerability Database
Dec 5, 2024
Published to the GitHub Advisory Database
Dec 5, 2024
Last updated
Dec 6, 2024
An “uninitialized variable” code execution vulnerability exists in the
Rockwell Automation Arena®
that could allow a threat actor to craft a DOE file and force the software to access a variable before it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
References