← Vulnerability feed

Vulnerability record · CVE-2019-13511 · published 15 August 2019

CVE-2019-13511: Rockwellautomation arena information exposure vulnerability

Rockwellautomation · Arena

Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION EXPOSURE CWE-200. A maliciously crafted Arena file opened by an unsuspecting user may result in the limited exposure of information related to the targeted workstation.

3.3 CVSS 3.1 Low EPSS 5.8% · top 7.2% CWE-200 · Information exposureCWE-416 · Use after free
3.3CVSS 3.1 base score, v2 4.3
5.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION EXPOSURE CWE-200. A maliciously crafted Arena file opened by an unsuspecting user may result in the limited exposure of information related to the targeted workstation.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-13511 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-29460Rockwellautomation arena out-of-bounds read vulnerabilityAn arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma…EPSS 0.85%9.8CVE-2023-29461Rockwellautomation arena out-of-bounds read vulnerabilityAn arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma…EPSS 0.85%8.8CVE-2023-29462Rockwellautomation arena out-of-bounds write vulnerabilityAn arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma…EPSS 0.90%8.5CVE-2025-3288Rockwellautomation arena out-of-bounds read vulnerabilityA local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memor…EPSS 0.30%8.5CVE-2025-3289Rockwellautomation arena out-of-bounds write vulnerabilityA local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of impr…EPSS 0.31%8.5CVE-2025-3285Rockwellautomation arena out-of-bounds read vulnerabilityA local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memor…EPSS 0.30%8.5CVE-2025-3286Rockwellautomation arena out-of-bounds read vulnerabilityA local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memor…EPSS 0.30%8.5CVE-2025-3287Rockwellautomation arena out-of-bounds read vulnerabilityA local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of impr…EPSS 0.31%

Source: NIST National Vulnerability Database (record CVE-2019-13511), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.