---
id: CVE-2025-11918
title: |-
  Rockwell Automation Arena® suffers from a
  stack-based buffer overflow vulnerability
summary: |-
  Rockwell Automation Arena® suffers from a
  stack-based buffer overflow vulnerability. The specific flaw exists within the
  parsing of DOE files. Local attackers are able to exploit this issue to
  potentially execute arbitrary code on affect…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-121
vendor: rockwellautomation
product: arena
affected:
  - arena < 16.20.11
patched:
  - arena 16.20.11
published: '2025-11-14'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11918'
references:
  - url: >-
      https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1763.html
    label: PSIRT@rockwellautomation.com
tags:
  - nvd
epss: 0.00156
epssPercentile: 0.04203
ingestedAt: '2026-10-07T21:54:15.038Z'
---

## Overview

Rockwell Automation Arena® suffers from a
stack-based buffer overflow vulnerability. The specific flaw exists within the
parsing of DOE files. Local attackers are able to exploit this issue to
potentially execute arbitrary code on affected installations of Arena®. Exploiting
the vulnerability requires opening a malicious DOE file.

## Affected

- `arena < 16.20.11`

## Remediation

Upgrade past the affected range:

- `arena 16.20.11`
