ZeroHour
Product

Historian ME

0 mentions in 7 days · 1 in 30 days · 1 total · first seen · last

Timeline

Rockwell Automation Historian ME

CISA warns CVE-2025-12768 and CVE-2026-12661 in Rockwell Historian ME could crash devices or allow remote code execution via out-of-bounds writes; CVSS 8.

CISA issued an ICS advisory for Rockwell Automation Historian ME Series B 5.202 and Series C 7.101. CVE-2025-12768 and CVE-2026-12661 involve out-of-bounds write and stack-based buffer overflow flaws that could crash the accessed device or enable remote code execution. The product is deployed across chemical, critical manufacturing, healthcare, and water and wastewater sectors worldwide.

Related CVEs

  • Out-of-bounds write in Rockwell FactoryTalk Historian Machine Edition allows RCE
    Rockwell Automation's FactoryTalk Historian Machine Edition contains an out-of-bounds write (CWE-787) that can be triggered by an attacker who holds low-level (low-privileged) authentication and can reach the historian over an adjacent network, as reflected in the CVSS 4.0 vector (AV:A/PR:L). By sending crafted input to the vulnerable service, the attacker corrupts memory beyond the intended buffer and achieves remote code execution on the host running the historian. Successful exploitation yields high impact to confidentiality, integrity, and availability on the affected system, effectively full compromise of that machine, with no modeled impact spreading to the wider network. Affected users are industrial operators, OEMs/machine builders, and plant sites running FactoryTalk Historian Machine Edition; the affected version ranges are specified in Rockwell Automation's security advisory and are not stated in the source data. Exploitation has not been observed: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates roughly a 0.3% probability of exploitation within 30 days.
    · Rockwell Automation FactoryTalk Historian Machine Editionlarge
  • Authenticated DoS via Buffer Overflow in Rockwell FactoryTalk Historian ME
    Rockwell Automation's FactoryTalk Historian Machine Edition contains a buffer overflow flaw (CWE-121) in its web interface. An attacker who is already on an adjacent network and holds valid, high-privileged credentials can send specially crafted requests to the web interface to trigger the overflow. Successful exploitation does not grant code execution or data theft; the impact is denial of service, causing the device to crash and become unresponsive until it is recovered. Only deployments running the affected FactoryTalk Historian Machine Edition web interface and reachable from an adjacent network segment are at risk. There is currently no known exploitation: the flaw is not in CISA's KEV, has a low EPSS score of 0.1%, and no public proof-of-concept is known.
    · Rockwell Automation FactoryTalk Historian Machine Editionmoderate

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.