Rockwell Automation has issued a security advisory addressing three memory abuse vulnerabilities in its Arena Simulation software, a widely used tool for discrete event simulation in manufacturing, logistics, healthcare, and supply chain modeling.
The vulnerabilities β CVE-2025-7025, CVE-2025-7032, and CVE-2025-7033 β all share the same characteristics and have been given a CVSS v3.1 base score of 7.8, indicating a High severity threat level.
Each of the three CVEs exposes Arena Simulation to the possibility of memory corruption, triggered when a user opens a maliciously crafted file or webpage:
- CVE-2025-7025
- CVE-2025-7032
- CVE-2025-7033
βA memory abuse issue exists in the affected product. A custom file can force Arena Simulation to read and write past the end of memory space,β the advisory explains.
This type of vulnerability can potentially lead to remote code execution (RCE) or information disclosure, depending on how the memory is manipulated during the attack.
Critically, these flaws require user interaction β such as opening a crafted file β but do not rely on system-level privileges or sophisticated malware deployment, making them feasible for use in targeted attacks or phishing campaigns within industrial environments.
According to Rockwell Automation, the vulnerabilities affect:
- Arena Simulation version 16.20.09 and earlier
They have been corrected in version 16.20.10 and later. Users can download the updated version via the official Rockwell Compatibility & Downloads Center.
Related Posts:
- Rockwell Arena Simulation Flaw: Remote Code Execution Via Malicious DOE Files
- SVG Files: The Emerging Vector of Cyber Threats
- Critical Vulnerabilities Found in Rockwell Automation FactoryTalk ThinManager
- Alert: “Brokewell” Malware – New Threat Targets Bank Users with Remote Device Takeover
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.