Impact
The vulnerability is an out‑of‑bounds write that leads to a buffer overflow when a network adjacent attacker who has been authenticated sends specially crafted requests to the FactoryTalk® Historian Machine Edition web interface. Exploitation of this flaw can cause the device to crash and become unresponsive, leading to a denial of service. The weakness is a classic stack-based buffer overflow (CWE‑121).
Affected Systems
The affected product is Rockwell Automation’s FactoryTalk® Historian Machine Edition. The advisory indicates that any installation of that product is susceptible; specific version details are not listed, so all deployments of the product should be assumed vulnerable until patched.
Risk and Exploitability
The CVSS score of 4.8 places the flaw in the medium category, and because the EPSS score is not published, the likelihood of exploitation remains unknown. The flaw is not listed in the CISA KEV catalog, suggesting no publicly known exploit yet. The attack requires authenticated access to the web interface, so network adjacency and valid credentials are prerequisites. Consequently, the risk is moderate but should be addressed promptly to prevent the potential loss of availability.
OpenCVE Enrichment