Disclosure summary
Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a malicious DOE file.
Source-reported weakness categories
CWE-121
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2025-11918
Open original source · Updated Oct 07, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| rockwellautomation | arena | * {"versionEndExcluding":"16.20.11"} |
Original records & references
- NIST NVD record
- CVE Program record
- www.rockwellautomation.com — Vendor Advisory
PUBLISHED 2025-11-14T09:15:45-05:00
MODIFIED 2026-10-07T17:10:00-04:00
INGESTED 2026-10-08T12:35:23-04:00