2024-12-17 17:04:01 +00:00

118 lines
3.7 KiB
JSON

{
"id": "CVE-2024-21920",
"sourceIdentifier": "PSIRT@rockwellautomation.com",
"published": "2024-03-26T16:15:11.277",
"lastModified": "2024-12-17T15:52:01.670",
"vulnStatus": "Analyzed",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "\n\n\nA memory buffer vulnerability in Rockwell Automation Arena Simulation could potentially let a threat actor read beyond the intended memory boundaries. This could reveal sensitive information and even cause the application to crash, resulting in a denial-of-service condition. To trigger this, the user would unwittingly need to open a malicious file shared by the threat actor.\n\n\n\n"
},
{
"lang": "es",
"value": "Una vulnerabilidad del b\u00fafer de memoria en Rockwell Automation Arena Simulation podr\u00eda permitir que un actor de amenazas lea m\u00e1s all\u00e1 de los l\u00edmites de memoria previstos. Esto podr\u00eda revelar informaci\u00f3n confidencial e incluso provocar que la aplicaci\u00f3n falle, lo que provocar\u00eda una condici\u00f3n de denegaci\u00f3n de servicio. Para desencadenar esto, el usuario tendr\u00eda que abrir, sin saberlo, un archivo malicioso compartido por el actor de la amenaza."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "PSIRT@rockwellautomation.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L",
"baseScore": 4.4,
"baseSeverity": "MEDIUM",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "NONE",
"availabilityImpact": "LOW"
},
"exploitabilityScore": 1.8,
"impactScore": 2.5
},
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 1.8,
"impactScore": 5.2
}
]
},
"weaknesses": [
{
"source": "PSIRT@rockwellautomation.com",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
},
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:rockwellautomation:arena:*:*:*:*:*:*:*:*",
"versionStartIncluding": "16.00.00",
"matchCriteriaId": "C8A71AA4-C01D-47F2-B87F-96EF9B461BD1"
}
]
}
]
}
],
"references": [
{
"url": "https://www.rockwellautomation.com/en-us/support/advisory.SD-1665.html",
"source": "PSIRT@rockwellautomation.com",
"tags": [
"Broken Link"
]
},
{
"url": "https://www.rockwellautomation.com/en-us/support/advisory.SD-1665.html",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Broken Link"
]
}
]
}