Remote Code Execution Vulnerability in FactoryTalk Historian Machine Edition by Rockwell Automation
CVE-2025-12768

8.6HIGH

What is CVE-2025-12768?

A security issue has been identified within FactoryTalk® Historian Machine Edition that allows attackers with minimal authentication to exploit the vulnerability. By leveraging this flaw, unauthorized individuals can execute remote code on the affected device, which could lead to further compromise of the system's integrity and confidentiality. Mitigation steps should be taken to secure affected installations.

Affected Version(s)

FactoryTalk® Historian Machine Edition Series C: 7.101 Series B: 5.202

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.