PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-12175 Rockwell Automation CVE debrief

A use-after-free vulnerability in Rockwell Automation Arena simulation software enables arbitrary code execution when a user opens a maliciously crafted DOE file. The flaw stems from improper memory management where freed resources are reused, allowing an attacker to hijack execution flow. Exploitation requires local access and user interaction—specifically, a legitimate user must execute the crafted file. The vulnerability carries a HIGH severity CVSS 3.1 score of 7.8, reflecting significant confidentiality, integrity, and availability impacts once the social engineering barrier is crossed. Rockwell Automation has addressed this in version 16.20.09 and later.

Vendor
Rockwell Automation
Product
Arena
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-12-10
Original CVE updated
2026-06-23
Advisory published
2024-12-10
Advisory updated
2026-06-23

Who should care

Engineering teams using Rockwell Automation Arena for discrete event simulation in manufacturing, logistics, and process design. OT security teams responsible for protecting engineering workstations. Asset owners in critical infrastructure sectors where Arena models are shared across organizational boundaries. Procurement and vendor management teams evaluating software supply chain risks for industrial software.

Technical summary

The vulnerability exists in Arena's handling of DOE (Discrete Event Optimization) files, where a use-after-free condition allows attackers to corrupt heap memory and achieve code execution. The attack vector is local (AV:L) with low attack complexity (AC:L), requiring no privileges (PR:N) but user interaction (UI:R). Successful exploitation yields high impact across confidentiality, integrity, and availability (C:H/I:H/A:H). The CVSS 4.0 vector (AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N) confirms consistent scoring. No network attack vector or privilege escalation is required post-exploitation.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade to Rockwell Automation Arena version 16.20.09 or later to remediate this vulnerability.
  • Avoid loading untrusted Arena model files from unverified sources.
  • Hold the Control key when opening files to prevent automatic VBA file stream loading.
  • Implement Rockwell Automation's published security best practices for industrial control systems.
  • Apply CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) framework for environment-specific prioritization.

Evidence notes

CVE published 2024-12-10; advisory updated 2025-01-09 (Update A) and 2026-02-03 (Update B). CWE-416 (Use After Free) classification confirmed via source references. Affected product: Rockwell Automation Arena ≤16.20.06.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-12175 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-12175

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-12175 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-12175

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-345-06.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-345-06

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.