CVE-2025-12768

8.6

Rockwell Automation · FactoryTalk Historian Machine Edition

Rockwell Automation FactoryTalk Historian Machine Edition contains an out-of-bounds write vulnerability that allows low-level authenticated attackers to achieve remote code execution.

Executive summary

A high-severity out-of-bounds write vulnerability in Rockwell Automation FactoryTalk Historian Machine Edition allows authenticated attackers to execute arbitrary code on the target device.

Vulnerability

This vulnerability is categorized as an out-of-bounds write (CWE-787) occurring within the historian software. An attacker who has achieved low-level authentication can trigger this flaw to achieve remote code execution on the affected device.

Business impact

The ability for an attacker to execute arbitrary code creates a significant risk of total system compromise, including potential loss of data integrity and availability for industrial processes. With a CVSS score of 8.6, this vulnerability represents a high threat to operational technology environments. Successful exploitation may lead to unauthorized control over the historian device, which could be leveraged to disrupt manufacturing or facility operations.

Remediation

Immediate Action: Review the official security advisory provided by Rockwell Automation and apply all recommended firmware or software updates as soon as they become available.

Proactive Monitoring: Monitor network traffic and system logs for anomalous activity, specifically focusing on unusual command execution patterns or unauthorized attempts to access historian services.

Compensating Controls: Implement network segmentation to restrict access to the historian device to only necessary personnel and systems, effectively limiting the potential for low-level authenticated attackers to reach the vulnerable endpoint.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for remote code execution and the critical nature of industrial historian software, this vulnerability poses a substantial risk to operational continuity. Administrators should prioritize the identification of affected Series B and Series C versions within their environment and coordinate with Rockwell Automation to deploy the necessary patches immediately upon release.

More Rockwell Automation CVEs

Sources