Executive brief
FactoryTalk Historian Machine Edition is an embedded data historian module used in industrial automation systems to collect and store time-series process data. An authenticated network-adjacent attacker can exploit a stack-based buffer overflow in the web interface by sending crafted requests, causing the device to crash and become temporarily unavailable, disrupting machine-level data collection and monitoring operations.
Technical details
This vulnerability is a stack-based buffer overflow (CWE-121) in FactoryTalk Historian Machine Edition's web interface. An attacker with low-level authentication credentials and network adjacency can send specially crafted requests that trigger the overflow condition. The overflow causes a denial-of-service condition, crashing the device and making it unresponsive until manually recovered. The vulnerability affects Historian ME Series B (version 5.202) and Series C (version 7.101), with fixes available in Series B version 5.203 and Series C version 7.102. No public exploit code is known, and patches are available.
Affected products
- Rockwell Automation FactoryTalk Historian Machine Edition Series B 5.202, Series C 7.101
Timeline
- 2026-09-01: disclosed: Security advisory SD1796 published