Executive brief
Rockwell Automation FactoryTalk Historian Site Edition, an industrial data platform used to collect and analyze process data, is vulnerable to an authentication bypass. By repeatedly sending requests to the login system, an unauthorized attacker can obtain a valid security token. This could allow an attacker to gain full access to sensitive industrial data and system configurations without providing legitimate credentials.
Technical details
An authentication bypass vulnerability (CWE-362) exists in FactoryTalk Historian Site Edition v11. The flaw is rooted in a race condition within the login endpoint's handling of concurrent requests. By flooding the endpoint with repeated requests, an unauthenticated attacker can trigger improper synchronization that results in the issuance of a valid authentication token. This allows for full unauthorized access (VC:H/VI:H) over the network without user interaction. Rockwell Automation has released version 12.00.00 to address this issue and provided a specific patch (BF32850) for users unable to upgrade immediately.
Affected products
- Rockwell Automation FactoryTalk Historian Site Edition (SE) v11
Timeline
- 2026-06-16: disclosed
- 2026-06-16: patched: Fixed in version 12.00.00 and patch BF32850