CVE-2025-11918 HIGH

CVE-2025-11918: Rockwell Automation Arena® Simulation Stack-Based Buffer Overflow Vulnerability

Vendor Rockwell Automation
Product Arena® Simulation
Weakness CWE-121
Published November 14, 2025
Last update November 14, 2025

CVSS base score

7.1/10
Attack vector Local
Attack complexity High
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a malicious DOE file.

Key dates

02Disclosure timeline

November 14, 2025 CVE published
November 14, 2025 Record updated