Impact
An out‑of‑bounds write flaw exists in FactoryTalk® Historian Machine Edition that permits an attacker possessing low‑level credentials to execute arbitrary code on the device. The vulnerability is a classic buffer overflow (CWE‑787) and, according to the advisory, leads directly to remote code execution.
Affected Systems
Rockwell Automation’s FactoryTalk Historian Machine Edition, with no specific version exclusions reported; all installations of the product are considered vulnerable unless otherwise noted by the manufacturer.
Risk and Exploitability
The CVSS score of 8.6 marks this as a high‑severity flaw, and while an EPSS score is not available, the vulnerability is implicitly exploitable over the network by anyone who can authenticate with low‑level access. It is not listed in the CISA KEV catalog, yet its potential impact warrants urgent attention. The attack vector is inferred to be remote access, given the need for network connectivity to the device and the allowance of low‑level authentication.
OpenCVE Enrichment