← Vulnerability feed

Vulnerability record · CVE-2019-13510 · published 15 August 2019

CVE-2019-13510: Rockwellautomation arena use after free vulnerability

Rockwellautomation · Arena

Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. A maliciously crafted Arena file opened by an unsuspecting user may result in the application crashing or the execution of arbitrary code.

7.8 CVSS 3.0 High EPSS 12% · top 4.0% CWE-416 · Use after free
7.8CVSS 3.0 base score, v2 6.8
12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
26References
17 Jun 2026Last modified by NVD

Description

Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. A maliciously crafted Arena file opened by an unsuspecting user may result in the application crashing or the execution of arbitrary code.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.us-cert.gov/ics/advisories/icsa-19-213-05 MitigationThird Party AdvisoryUS Government Resource
https://www.zerodayinitiative.com/advisories/ZDI-19-1000/
https://www.zerodayinitiative.com/advisories/ZDI-19-800/
https://www.zerodayinitiative.com/advisories/ZDI-19-801/
https://www.zerodayinitiative.com/advisories/ZDI-19-994/
https://www.zerodayinitiative.com/advisories/ZDI-19-998/
https://www.zerodayinitiative.com/advisories/ZDI-19-999/
https://www.zerodayinitiative.com/advisories/ZDI-20-926/
https://www.zerodayinitiative.com/advisories/ZDI-20-927/
https://www.zerodayinitiative.com/advisories/ZDI-20-928/
https://www.zerodayinitiative.com/advisories/ZDI-20-929/
https://www.zerodayinitiative.com/advisories/ZDI-20-930/
https://www.zerodayinitiative.com/advisories/ZDI-20-931/
https://www.us-cert.gov/ics/advisories/icsa-19-213-05 MitigationThird Party AdvisoryUS Government Resource
https://www.zerodayinitiative.com/advisories/ZDI-19-1000/
https://www.zerodayinitiative.com/advisories/ZDI-19-800/
https://www.zerodayinitiative.com/advisories/ZDI-19-801/
https://www.zerodayinitiative.com/advisories/ZDI-19-994/
https://www.zerodayinitiative.com/advisories/ZDI-19-998/
https://www.zerodayinitiative.com/advisories/ZDI-19-999/
https://www.zerodayinitiative.com/advisories/ZDI-20-926/
https://www.zerodayinitiative.com/advisories/ZDI-20-927/
https://www.zerodayinitiative.com/advisories/ZDI-20-928/
https://www.zerodayinitiative.com/advisories/ZDI-20-929/
https://www.zerodayinitiative.com/advisories/ZDI-20-930/
https://www.zerodayinitiative.com/advisories/ZDI-20-931/

Track CVE-2019-13510 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-29460Rockwellautomation arena out-of-bounds read vulnerabilityAn arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma…EPSS 0.85%9.8CVE-2023-29461Rockwellautomation arena out-of-bounds read vulnerabilityAn arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma…EPSS 0.85%8.8CVE-2023-29462Rockwellautomation arena out-of-bounds write vulnerabilityAn arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma…EPSS 0.90%8.5CVE-2025-3288Rockwellautomation arena out-of-bounds read vulnerabilityA local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memor…EPSS 0.30%8.5CVE-2025-3289Rockwellautomation arena out-of-bounds write vulnerabilityA local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of impr…EPSS 0.31%8.5CVE-2025-3285Rockwellautomation arena out-of-bounds read vulnerabilityA local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memor…EPSS 0.30%8.5CVE-2025-3286Rockwellautomation arena out-of-bounds read vulnerabilityA local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memor…EPSS 0.30%8.5CVE-2025-3287Rockwellautomation arena out-of-bounds read vulnerabilityA local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of impr…EPSS 0.31%

Source: NIST National Vulnerability Database (record CVE-2019-13510), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.