Rockwell Automation Historian ME
CISA warns CVE-2025-12768 and CVE-2026-12661 in Rockwell Historian ME could crash devices or allow remote code execution via out-of-bounds writes; CVSS 8.
CISA issued an ICS advisory for Rockwell Automation Historian ME Series B 5.202 and Series C 7.101. CVE-2025-12768 and CVE-2026-12661 involve out-of-bounds write and stack-based buffer overflow flaws that could crash the accessed device or enable remote code execution. The product is deployed across chemical, critical manufacturing, healthcare, and water and wastewater sectors worldwide.
- Out-of-bounds write may allow remote code execution
- Historian ME Series B 5.202 and Series C 7.101 affected
- CVSS v3 base score of 8.0
- Used in chemical, healthcare, and water infrastructure
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-12768 | Out-of-bounds write in Rockwell FactoryTalk Historian Machine Edition allows RCE Rockwell Automation's FactoryTalk Historian Machine Edition contains an out-of-bounds write (CWE-787) that can be triggered by an attacker who holds low-level (low-privileged) authentication and can reach the historian over an adjacent network, as reflected in the CVSS 4.0 vector (AV:A/PR:L). By sending crafted input to the vulnerable service, the attacker corrupts memory beyond the intended buffer and achieves remote code execution on the host running the historian. Successful exploitation yields high impact to confidentiality, integrity, and availability on the affected system, effectively full compromise of that machine, with no modeled impact spreading to the wider network. Affected users are industrial operators, OEMs/machine builders, and plant sites running FactoryTalk Historian Machine Edition; the affected version ranges are specified in Rockwell Automation's security advisory and are not stated in the source data. Exploitation has not been observed: the flaw is not in CISA's KEV, no public proof-of-concept is known, and EPSS estimates roughly a 0.3% probability of exploitation within 30 days. Do: Check the Rockwell Automation PSIRT advisory for CVE-2025-12768 for the exact affected version ranges and apply the vendor's recommended software/firmware update. Because exploitation requires network adjacency plus valid low-privileged credentials, restrict access to the historian's network ports (OT segmentation/firewall rules), review and rotate shared or default low-privilege accounts with access to the historian, and monitor hosts running the historian for anomalous process activity. | 8.6 | <1% |
| large≈ tens of thousands of installed machines/sites worldwide (estimated) | ||
| CVE-2026-12661 | Authenticated DoS via Buffer Overflow in Rockwell FactoryTalk Historian ME Rockwell Automation's FactoryTalk Historian Machine Edition contains a buffer overflow flaw (CWE-121) in its web interface. An attacker who is already on an adjacent network and holds valid, high-privileged credentials can send specially crafted requests to the web interface to trigger the overflow. Successful exploitation does not grant code execution or data theft; the impact is denial of service, causing the device to crash and become unresponsive until it is recovered. Only deployments running the affected FactoryTalk Historian Machine Edition web interface and reachable from an adjacent network segment are at risk. There is currently no known exploitation: the flaw is not in CISA's KEV, has a low EPSS score of 0.1%, and no public proof-of-concept is known. Do: Check the Rockwell Automation security advisory (PSIRT) for this CVE to identify affected versions and apply the vendor's fixed release when available, since no fixed version numbers are provided in this data. In the meantime, restrict access to the Historian Machine Edition web interface to trusted network segments, minimize the number of high-privilege accounts that can authenticate to it, and monitor affected devices for unexpected crashes or unresponsiveness. If a device becomes unresponsive, treat loss of historian service as the expected impact and plan recovery/monitoring accordingly. | 4.8 | <1% |
| moderatelikely thousands of machine-level installations globally, though many are isolated from attacker-reachable networks |
View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution. The following versions of Rockwell Automation Historian ME are affected: Series B 5.202 (CVE-2025-12768, CVE-2026-12661) Series C 7.101 (CVE-2025-12768, CVE-2026-12661) CVSS Vendor Equipment Vulnerabilities v3 8 Rockwell Automation Rockwell Automation Historian ME Out-of-bounds Write, Stack-based Buffer Overflow Background Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Food and Agriculture, Healthcare and Public Health, Water and Wastewater Systems Countries/Areas Deployed: Worldwide Company…
This source does not provide full text. Read it at cisa.gov.