PatchSiren cyber security CVE debrief
CVE-2024-12130 Rockwell Automation CVE debrief
CVE-2024-12130 is a high-severity out-of-bounds read vulnerability in Rockwell Automation Arena simulation software, published by CISA on December 10, 2024, with an advisory update (Update B) issued February 3, 2026. The flaw exists in Arena versions 16.20.05 and earlier, where a crafted DOE (Design of Experiments) file can force the application to read beyond allocated memory boundaries. Successful exploitation enables arbitrary code execution in the context of the legitimate user who opens the malicious file. The attack requires local access and user interaction, with a CVSS 3.1 score of 7.8 (HIGH). Rockwell Automation has released version 16.20.09 to address this vulnerability.
- Vendor
- Rockwell Automation
- Product
- Arena
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-12-10
- Original CVE updated
- 2026-06-23
- Advisory published
- 2024-12-10
- Advisory updated
- 2026-06-23
Who should care
Engineering teams using Rockwell Automation Arena for discrete event simulation in manufacturing, logistics, and industrial process design; OT security practitioners responsible for protecting engineering workstations; asset owners in critical infrastructure sectors where Arena is deployed for process optimization and simulation activities.
Technical summary
The vulnerability stems from improper bounds checking when parsing DOE files in Rockwell Automation Arena simulation software. A threat actor can craft a malicious DOE file that, when opened by a legitimate user, triggers an out-of-bounds memory read. This memory safety violation can be leveraged to achieve arbitrary code execution. The attack vector is local, requiring user interaction to open the malicious file. The vulnerability is classified under CWE-125 (Out-of-bounds Read).
Defensive priority
HIGH
Recommended defensive actions
- Upgrade Rockwell Automation Arena to version 16.20.09 or later to remediate this vulnerability
- Do not open untrusted Arena model files or DOE files from unverified sources
- Hold the Control key when loading files to prevent VBA file stream from loading as a temporary mitigation
- Implement Rockwell Automation's security best practices for industrial control systems
- Apply network segmentation and least-privilege principles to limit exposure of engineering workstations
- Consider using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) for environment-specific prioritization
Evidence notes
CVE published 2024-12-10; advisory modified 2026-02-03 (Update B). CWE-125 (Out-of-bounds Read). Affected product: Rockwell Automation Arena ≤16.20.05. Fix version: 16.20.09 or later.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-12130 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-12130
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-12130 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-12130
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-345-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.