CVE-2025-12768
Received Received - Intake

Remote Code Execution in FactoryTalk Historian Machine Edition

Vulnerability report for CVE-2025-12768, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-01

Last updated on: 2026-09-01

Assigner: Rockwell Automation

Description

A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code execution on the affected device.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-01
Last Modified
2026-09-01
Generated
2026-09-01
AI Q&A
2026-09-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
rockwellautomation factorytalk_historian_machine_edition *
rockwell_automation factorytalk_historian_machine_edition to 7.102 (exc)
rockwell_automation factorytalk_historian_machine_edition to 5.203 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2025-12768 is an out-of-bounds write vulnerability in Rockwell Automation's FactoryTalk Historian Machine Edition (ME) versions 7.101 and 5.202. An attacker with low-level authentication can exploit this to achieve remote code execution on the affected device.

Impact Analysis

An attacker could gain control of the affected device, potentially leading to unauthorized access, data manipulation, or disruption of operations in industrial environments using FactoryTalk Historian ME.

Compliance Impact

The vulnerability allows remote code execution with low-level authentication, which could lead to unauthorized access or data breaches. This may impact compliance with GDPR or HIPAA if sensitive data is exposed or altered. However, specific compliance impacts are not detailed in the provided context.

Mitigation Strategies

Update FactoryTalk Historian Machine Edition to versions 7.102 or 5.203 or later to address the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-12768. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart