
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-11918 is a stack-based buffer overflow vulnerability in Rockwell Automation Arena® Simulation software affecting versions 16.20.10 and prior (fixed in 16.20.11). The flaw exists within the parsing of DOE files, allowing local attackers to potentially execute arbitrary code when a victim opens a malicious DOE file. It was published on November 14, 2025, with a patch advisory released shortly after. The vulnerability carries a CVSS v3.1 base score of 7.3 (High) and a CVSS v4.0 base score of 7.1 (High) (Rockwell Advisory, CISA ICS Advisory).
The vulnerability is classified as CWE-121 (Stack-based Buffer Overflow), rooted in insufficient bounds checking during the parsing of DOE (Design of Experiments) files within Rockwell Automation Arena®. An attacker can craft a malicious DOE file that, when opened by a user, triggers a stack buffer overflow, potentially overwriting return addresses or control data to redirect execution flow. Exploitation requires local access and active user interaction — specifically, the victim must open the crafted file — making this a file-format parsing attack typical of simulation and engineering software (Rockwell Advisory, CISA ICS Advisory).
Successful exploitation of CVE-2025-11918 can result in arbitrary code execution on the affected workstation with the privileges of the user running Arena®. This leads to high confidentiality, integrity, and availability impacts on the local system, potentially enabling an attacker to steal sensitive simulation data, tamper with engineering models, or install malware. Given that Arena® is used in industrial and manufacturing environments, compromise of a workstation running this software could serve as a foothold for further lateral movement within operational technology (OT) or enterprise networks (Rockwell Advisory, CISA ICS Advisory).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-11918 as of the available data. The EPSS score is approximately 0.016% (0.000160), indicating a very low probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, though CISA did release an ICS advisory (ICSA-25-329-02) on November 25, 2025, highlighting the issue for industrial control system operators (CISA ICS Advisory, CISA Alert).
cmd.exe, powershell.exe, wscript.exe); Arena® crashing or generating application error logs when opening specific DOE files.Rockwell Automation has released Arena® version 16.20.11 to address this vulnerability, and users should upgrade immediately. As interim mitigations, organizations should restrict access to Arena® workstations, avoid opening DOE files from untrusted or unknown sources, and apply the principle of least privilege to user accounts running Arena®. CISA also recommends minimizing network exposure for ICS/SCADA systems and using secure file transfer practices (Rockwell Advisory, CISA ICS Advisory).
CISA released ICS Advisory ICSA-25-329-02 on November 25, 2025, as part of a batch of seven ICS advisories, drawing attention from the industrial cybersecurity community (CISA Alert). The vulnerability was noted in the Hawk-Eye weekly threat landscape digest for Week 49 of 2025, indicating moderate community tracking (Hawk-Eye Digest). No significant social media controversy or major researcher commentary beyond standard vulnerability tracking has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."