Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
                
            References
                    | Link | Resource | 
|---|---|
| https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html | Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
History
                    11 Jul 2025, 20:03
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time | Microsoft windows Microsoft | |
| CPE | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:* cpe:2.3:a:rockwellautomation:arena:*:*:*:*:*:*:*:* | 
21 Jan 2025, 21:26
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:rockwellautomation:arena:*:*:*:*:*:*:x32:* | |
| First Time | Rockwellautomation arena Rockwellautomation | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 7.3 | 
| Summary | 
 | |
| CWE | CWE-908 | |
| References | () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1713.html - Vendor Advisory | 
19 Dec 2024, 21:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-12-19 21:15
Updated : 2025-07-11 20:03
NVD link : CVE-2024-11364
Mitre link : CVE-2024-11364
CVE.ORG link : CVE-2024-11364
JSON object : View
Products Affected
                microsoft
- windows
rockwellautomation
- arena
CWE
                
                    
                        
                        CWE-908
                        
            Use of Uninitialized Resource
