{"id":"CVE-2025-11918","title":"Rockwell Automation Arena® suffers from a\nstack-based buffer overflow vulnerability","summary":"Rockwell Automation Arena® suffers from a\nstack-based buffer overflow vulnerability. The specific flaw exists within the\nparsing of DOE files. Local attackers are able to exploit this issue to\npotentially execute arbitrary code on affect…","severity":"high","cvss":7.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-121"],"vendor":"rockwellautomation","product":"arena","affected":["arena < 16.20.11"],"patched":["arena 16.20.11"],"published":"2025-11-14","updated":"2026-10-07","sourceUpdated":"2026-10-07T21:10:00.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-11918","references":[{"url":"https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1763.html","label":"PSIRT@rockwellautomation.com"}],"tags":["nvd"],"epss":0.00156,"epssPercentile":0.04203,"ingestedAt":"2026-10-07T21:54:15.038Z","slug":"CVE-2025-11918","body":"## Overview\n\nRockwell Automation Arena® suffers from a\nstack-based buffer overflow vulnerability. The specific flaw exists within the\nparsing of DOE files. Local attackers are able to exploit this issue to\npotentially execute arbitrary code on affected installations of Arena®. Exploiting\nthe vulnerability requires opening a malicious DOE file.\n\n## Affected\n\n- `arena < 16.20.11`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `arena 16.20.11`","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":40.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}