ZeroHour

CVE-2026-12661

moderate

Authenticated DoS via Buffer Overflow in Rockwell FactoryTalk Historian ME

CVSS 4.0
4.8 medium
EPSS
<1%p4
Published
()
Modified
AI analysis

Rockwell Automation's FactoryTalk Historian Machine Edition contains a buffer overflow flaw (CWE-121) in its web interface. An attacker who is already on an adjacent network and holds valid, high-privileged credentials can send specially crafted requests to the web interface to trigger the overflow. Successful exploitation does not grant code execution or data theft; the impact is denial of service, causing the device to crash and become unresponsive until it is recovered. Only deployments running the affected FactoryTalk Historian Machine Edition web interface and reachable from an adjacent network segment are at risk. There is currently no known exploitation: the flaw is not in CISA's KEV, has a low EPSS score of 0.1%, and no public proof-of-concept is known.

What to do: Check the Rockwell Automation security advisory (PSIRT) for this CVE to identify affected versions and apply the vendor's fixed release when available, since no fixed version numbers are provided in this data. In the meantime, restrict access to the Historian Machine Edition web interface to trusted network segments, minimize the number of high-privilege accounts that can authenticate to it, and monitor affected devices for unexpected crashes or unresponsiveness. If a device becomes unresponsive, treat loss of historian service as the expected impact and plan recovery/monitoring accordingly.

Affected
Rockwell Automation FactoryTalk Historian Machine Edition
Estimated exposure
moderatelikely thousands of machine-level installations globally, though many are isolated from attacker-reachable networks — Historian Machine Edition is a per-machine/embedded historian typically deployed by OEMs and machine builders rather than site-wide, and its web interface is rarely exposed beyond the local machine network; no public install counts or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive.

Weakness
CWE-121
Vector
CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Rockwell Automation Historian ME

CISA warns CVE-2025-12768 and CVE-2026-12661 in Rockwell Historian ME could crash devices or allow remote code execution via out-of-bounds writes; CVSS 8.

CISA issued an ICS advisory for Rockwell Automation Historian ME Series B 5.202 and Series C 7.101. CVE-2025-12768 and CVE-2026-12661 involve out-of-bounds write and stack-based buffer overflow flaws that could crash the accessed device or enable remote code execution. The product is deployed across chemical, critical manufacturing, healthcare, and water and wastewater sectors worldwide.