CVE-2024-6068 Vulnerability Details
/
/
/
CVE-2024-6068 Metadata Quick Info
CVE Published: 14/11/2024 |
CVE Updated: 14/11/2024 |
CVE Year: 2024
Source: Rockwell |
Vendor: Rockwell Automation |
Product: Arena Input Analyzer
Status : PUBLISHED
CVE-2024-6068 Description
A memory corruption vulnerability exists in the affected products when parsing DFT files. Local threat actors can exploit this issue to disclose information and to execute arbitrary code. To exploit this vulnerability a legitimate user must open a malicious DFT file.
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID: CWE-1284
CWE Name: CWE-1284 Improper Validation of Specified Quantity in Input
Source: Rockwell Automation
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID: CAPEC-549
CAPEC Description: CAPEC-549 Local Execution of Code
Source: NVD (National Vulnerability Database).