← Vulnerability feed

Vulnerability record · CVE-2019-13521 · published 27 January 2020

CVE-2019-13521: Rockwellautomation arena vulnerability

Rockwellautomation · Arena

A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may result in the limited exposure of information related to the targeted workstation. Rockwell Automation has released version 16.00.01 of Arena Simulation Software to address the reported vulnerabilities.

7.8 CVSS 3.1 High EPSS 5.6% · top 7.4% CWE-357 · CWE-357
7.8CVSS 3.1 base score, v2 6.8
5.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may result in the limited exposure of information related to the targeted workstation. Rockwell Automation has released version 16.00.01 of Arena Simulation Software to address the reported vulnerabilities.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.us-cert.gov/ics/advisories/icsa-19-213-05 Third Party AdvisoryUS Government Resource
https://www.zerodayinitiative.com/advisories/ZDI-19-799/ Third Party AdvisoryVDB Entry
https://www.us-cert.gov/ics/advisories/icsa-19-213-05 Third Party AdvisoryUS Government Resource
https://www.zerodayinitiative.com/advisories/ZDI-19-799/ Third Party AdvisoryVDB Entry

Track CVE-2019-13521 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-29460Rockwellautomation arena out-of-bounds read vulnerabilityAn arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma…EPSS 0.85%9.8CVE-2023-29461Rockwellautomation arena out-of-bounds read vulnerabilityAn arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma…EPSS 0.85%8.8CVE-2023-29462Rockwellautomation arena out-of-bounds write vulnerabilityAn arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma…EPSS 0.90%8.5CVE-2025-3288Rockwellautomation arena out-of-bounds read vulnerabilityA local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memor…EPSS 0.30%8.5CVE-2025-3289Rockwellautomation arena out-of-bounds write vulnerabilityA local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of impr…EPSS 0.31%8.5CVE-2025-3285Rockwellautomation arena out-of-bounds read vulnerabilityA local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memor…EPSS 0.30%8.5CVE-2025-3286Rockwellautomation arena out-of-bounds read vulnerabilityA local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memor…EPSS 0.30%8.5CVE-2025-3287Rockwellautomation arena out-of-bounds read vulnerabilityA local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of impr…EPSS 0.31%

Source: NIST National Vulnerability Database (record CVE-2019-13521), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.