Rockwell Automation Historian ME

Plan PatchCVSS 8ICS-CERT ICSA-26-244-06Sep 1, 2026
Rockwell Automation
Attack path
Attack VectorAdjacent
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Rockwell Historian Series B (5.202) and Series C (7.101), and FactoryTalk Historian Machine Edition contain out-of-bounds write vulnerabilities that could allow remote code execution or device crashes. An attacker can send malformed network packets to trigger memory corruption. Series B and C have mitigations available; FactoryTalk Historian Machine Edition has no fix planned.

What this means
What could happen
An attacker with network access to a Rockwell Historian device could execute arbitrary code on the device, potentially taking control of your historical data logging and reporting system or causing it to crash and stop recording process data.
Who's at risk
Plant historians and data logging operators using Rockwell Historian Series B, Series C, or FactoryTalk Historian Machine Edition. This affects any facility relying on these devices for process data archiving, reporting, and compliance record-keeping in manufacturing, utilities, and process industries.
How it could be exploited
An attacker sends a specially crafted network message to the Historian that triggers an out-of-bounds write in memory. This corrupts data on the device, either crashing it or allowing the attacker to run arbitrary commands with the privileges of the Historian process.
Prerequisites
  • Network access to the Historian device on its listening port
  • Low privileges (does not require administrator credentials)
  • No user interaction needed
remotely exploitablelow authentication requiredlow complexityno patch available for FactoryTalk Historian Machine Editionaffects data integrity and system availability
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (3)
2 pending1 EOL
ProductAffected VersionsFix Status
Series B: 5.2025.202No fix yet
Series C: 7.1017.101No fix yet
FactoryTalk Historian Machine EditionAll versionsNo fix (EOL)
Remediation & Mitigation
0/4
Do now
0/2
HARDENINGRestrict network access to Historian devices to trusted engineering workstations and control system networks only; use firewalls or network segmentation to block untrusted access
WORKAROUNDIf you are running Series B 5.202 or Series C 7.101 Historian, contact Rockwell Automation support to obtain and apply available mitigations
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HARDENINGReview and apply Rockwell Automation security best practices from their security documentation
Mitigations - no patch available
0/1
FactoryTalk Historian Machine Edition has reached End of Life. The vendor will not release a patch. Apply the following compensating controls:
HARDENINGFor FactoryTalk Historian Machine Edition (all versions with no vendor fix available), implement compensating controls: air-gap or isolate the device from untrusted networks, monitor process data integrity separately, and document the risk
API: /api/v1/advisories/f1025641-996a-47ab-ad0e-157e64cbd4ae

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Rockwell Automation Historian ME | CVSS 8 - OTPulse