A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition.  A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition.  A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive.
Title FactoryTalk® Historian Machine Edition - Out-of-Bounds Write Vulnerability
First Time appeared Rockwell Automation
Rockwell Automation factorytalk Historian Machine Edition
Weaknesses CWE-121
CPEs cpe:2.3:a:rockwell_automation:factorytalk_historian_machine_edition:series_c_7.101_series_b_5.202:*:*:*:*:*:*:*
Vendors & Products Rockwell Automation
Rockwell Automation factorytalk Historian Machine Edition
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2026-09-02T12:52:36.085Z

Reserved: 2026-06-18T18:59:07.379Z

Link: CVE-2026-12661

cve-icon Vulnrichment

Updated: 2026-09-01T15:49:15.388Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-01T14:17:24.133

Modified: 2026-09-01T20:50:01.960

Link: CVE-2026-12661

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T15:30:04Z

Weaknesses