AI analysis
Rockwell Automation's FactoryTalk Historian Machine Edition contains a buffer overflow flaw (CWE-121) in its web interface. An attacker who is already on an adjacent network and holds valid, high-privileged credentials can send specially crafted requests to the web interface to trigger the overflow. Successful exploitation does not grant code execution or data theft; the impact is denial of service, causing the device to crash and become unresponsive until it is recovered. Only deployments running the affected FactoryTalk Historian Machine Edition web interface and reachable from an adjacent network segment are at risk. There is currently no known exploitation: the flaw is not in CISA's KEV, has a low EPSS score of 0.1%, and no public proof-of-concept is known.
What to do: Check the Rockwell Automation security advisory (PSIRT) for this CVE to identify affected versions and apply the vendor's fixed release when available, since no fixed version numbers are provided in this data. In the meantime, restrict access to the Historian Machine Edition web interface to trusted network segments, minimize the number of high-privilege accounts that can authenticate to it, and monitor affected devices for unexpected crashes or unresponsiveness. If a device becomes unresponsive, treat loss of historian service as the expected impact and plan recovery/monitoring accordingly.
Affected
| Rockwell Automation FactoryTalk Historian Machine Edition | — |
Estimated exposure
moderatelikely thousands of machine-level installations globally, though many are isolated from attacker-reachable networks — Historian Machine Edition is a per-machine/embedded historian typically deployed by OEMs and machine builders rather than site-wide, and its web interface is rarely exposed beyond the local machine network; no public install counts or…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive.