Description
A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition.  A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive.
Published: 2026-09-01
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an out‑of‑bounds write that leads to a buffer overflow when a network adjacent attacker who has been authenticated sends specially crafted requests to the FactoryTalk® Historian Machine Edition web interface. Exploitation of this flaw can cause the device to crash and become unresponsive, leading to a denial of service. The weakness is a classic stack-based buffer overflow (CWE‑121).

Affected Systems

The affected product is Rockwell Automation’s FactoryTalk® Historian Machine Edition. The advisory indicates that any installation of that product is susceptible; specific version details are not listed, so all deployments of the product should be assumed vulnerable until patched.

Risk and Exploitability

The CVSS score of 4.8 places the flaw in the medium category, and because the EPSS score is not published, the likelihood of exploitation remains unknown. The flaw is not listed in the CISA KEV catalog, suggesting no publicly known exploit yet. The attack requires authenticated access to the web interface, so network adjacency and valid credentials are prerequisites. Consequently, the risk is moderate but should be addressed promptly to prevent the potential loss of availability.

Generated by OpenCVE AI on September 1, 2026 at 15:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the vendor‑released patch from Rockwell Automation for FactoryTalk® Historian Machine Edition.
  • If a patch is not yet available, restrict web interface access to trusted networks and enforce strong authentication policies.
  • Monitor for abnormal restarts or crashes and configure automatic restarts or failover mechanisms to mitigate service interruption.

Generated by OpenCVE AI on September 1, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation factorytalk Historian Machine Edition
Vendors & Products Rockwellautomation
Rockwellautomation factorytalk Historian Machine Edition

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition.  A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive.
Title FactoryTalk® Historian Machine Edition - Out-of-Bounds Write Vulnerability
First Time appeared Rockwell Automation
Rockwell Automation factorytalk Historian Machine Edition
Weaknesses CWE-121
CPEs cpe:2.3:a:rockwell_automation:factorytalk_historian_machine_edition:series_c_7.101_series_b_5.202:*:*:*:*:*:*:*
Vendors & Products Rockwell Automation
Rockwell Automation factorytalk Historian Machine Edition
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Rockwell Automation Factorytalk Historian Machine Edition
Rockwellautomation Factorytalk Historian Machine Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-09-02T12:52:36.085Z

Reserved: 2026-06-18T18:59:07.379Z

Link: CVE-2026-12661

cve-icon Vulnrichment

Updated: 2026-09-01T15:49:15.388Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T14:17:24.133

Modified: 2026-09-01T20:50:01.960

Link: CVE-2026-12661

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T16:27:59Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow