Description
A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition.  A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive.
Published: 2026-09-01
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition.  A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive.
Title FactoryTalk® Historian Machine Edition - Out-of-Bounds Write Vulnerability
First Time appeared Rockwell Automation
Rockwell Automation factorytalk Historian Machine Edition
Weaknesses CWE-121
CPEs cpe:2.3:a:rockwell_automation:factorytalk_historian_machine_edition:series_c_7.101_series_b_5.202:*:*:*:*:*:*:*
Vendors & Products Rockwell Automation
Rockwell Automation factorytalk Historian Machine Edition
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Rockwell Automation Factorytalk Historian Machine Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-09-02T12:52:36.085Z

Reserved: 2026-06-18T18:59:07.379Z

Link: CVE-2026-12661

cve-icon Vulnrichment

Updated: 2026-09-01T15:49:15.388Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T14:17:24.133

Modified: 2026-09-01T20:50:01.960

Link: CVE-2026-12661

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T15:30:04Z

Weaknesses