CVE-2024-6068 Vulnerability Details

  /     /     /  

CVE-2024-6068 Metadata Quick Info

CVE Published: 14/11/2024 | CVE Updated: 14/11/2024 | CVE Year: 2024
Source: Rockwell | Vendor: Rockwell Automation | Product: Arena Input Analyzer
Status : PUBLISHED

CVE-2024-6068 Description

A memory corruption vulnerability exists in the affected products when parsing DFT files. Local threat actors can exploit this issue to disclose information and to execute arbitrary code. To exploit this vulnerability a legitimate user must open a malicious DFT file.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-1284
CWE Name: CWE-1284 Improper Validation of Specified Quantity in Input
Source: Rockwell Automation

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-549
CAPEC Description: CAPEC-549 Local Execution of Code


Source: NVD (National Vulnerability Database).