Executive brief
Rockwell Automation Arena is industrial simulation software used for manufacturing and logistics modeling. Multiple memory corruption vulnerabilities exist when parsing specially crafted DOE files, allowing remote code execution if a user opens a malicious file. An attacker could gain full control of the affected system and disrupt critical industrial operations.
Technical details
CVE-2026-6071 is an out-of-bounds write vulnerability in Arena's DOE file parser. The vulnerability exists due to improper bounds checking when processing file content, allowing an attacker to write past allocated memory boundaries and execute arbitrary code in the application's context. Attack requires a legitimate user to open a malicious DOE file (local attack vector with user interaction). Patches are available: Arena versions 16.20.09 and later for this specific CVE, with partial fixes in earlier versions for related issues.
Affected products
- Rockwell Automation Arena 16.20.08 and prior
Timeline
- 2026-09-03: disclosed
- 2026-09-03: patched: Version 16.20.09 or later contains fix