CVE-2024-21919

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 26, 2024
CWE ID 824

Summary

CVE-2024-21919 is a vulnerability affecting Rockwell Automation Arena Simulation software. An uninitialized pointer in the software may allow a malicious user to inject unauthorized code, potentially leading to data compromise or system takeover. Triggering this issue requires opening a specially crafted file provided by the attacker. This vulnerability poses risks to the confidentiality, integrity, and availability of the product.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share