ZeroHour

CVE-2025-12768

large

Out-of-bounds write in Rockwell FactoryTalk Historian Machine Edition allows RCE

CVSS 4.0
8.6 high
EPSS
<1%p21
Published
()
Modified
AI analysis

Rockwell Automation's FactoryTalk Historian Machine Edition contains an out-of-bounds write (CWE-787) that can be triggered by an attacker who holds low-level (low-privileged) authentication and can reach the historian over an adjacent network, as reflected in the CVSS 4.0 vector (AV:A/PR:L). By sending crafted input to the vulnerable service, the attacker corrupts memory beyond the intended buffer and achieves remote code execution on the host running the historian. Successful exploitation yields high impact to confidentiality, integrity, and availability on the affected system, effectively full compromise of that machine, with no modeled impact spreading to the wider network. Affected users are industrial operators, OEMs/machine builders, and plant sites running FactoryTalk Historian Machine Edition; the affected version ranges are specified in Rockwell Automation's security advisory and are not stated in the source data. Exploitation has not been observed: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates roughly a 0.3% probability of exploitation within 30 days.

What to do: Check the Rockwell Automation PSIRT advisory for CVE-2025-12768 for the exact affected version ranges and apply the vendor's recommended software/firmware update. Because exploitation requires network adjacency plus valid low-privileged credentials, restrict access to the historian's network ports (OT segmentation/firewall rules), review and rotate shared or default low-privilege accounts with access to the historian, and monitor hosts running the historian for anomalous process activity.

Affected
Rockwell Automation FactoryTalk Historian Machine Edition
Estimated exposure
large≈ tens of thousands of installed machines/sites worldwide (estimated) — Estimate based on deployment patterns and market share: FactoryTalk Historian Machine Edition is installed per machine or production line across Rockwell Automation's very large industrial automation installed base, but no public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code execution on the affected device.

Weakness
CWE-787
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Rockwell Automation Historian ME

CISA warns CVE-2025-12768 and CVE-2026-12661 in Rockwell Historian ME could crash devices or allow remote code execution via out-of-bounds writes; CVSS 8.

CISA issued an ICS advisory for Rockwell Automation Historian ME Series B 5.202 and Series C 7.101. CVE-2025-12768 and CVE-2026-12661 involve out-of-bounds write and stack-based buffer overflow flaws that could crash the accessed device or enable remote code execution. The product is deployed across chemical, critical manufacturing, healthcare, and water and wastewater sectors worldwide.