What happened
The following versions of Rockwell Automation Historian ME are affected: Series B 5.202 (CVE-2025-12768, CVE-2026-12661) Series C 7.101 (CVE-2025-12768, CVE-2026-12661) CVSS Vendor Equipment Vulnerabilities v3 8 Rockwell Automation Rockwell Automation Historian ME Out-of-bounds Write, Stack-based Buffer Overflow Background…
An attacker with low-level authentication could exploit this vulnerability to achieveremote code execution on the affected device.
What is verified
View CVE Details Affected Products Rockwell Automation Historian ME Vendor: Rockwell Automation Product Version: Rockwell Automation Series B: 5.202, Rockwell Automation Series C: 7.101 Product Status: known_affected Remediations Mitigation Customers using the affected software, who are not able…
More information can be found at https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html.
https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html Mitigation If you have any questions regarding this disclosure, please contact PSIRT Email: [email protected] mailto:[email protected] Relevant CWE: CWE-787 Out-of-bounds Write Metrics CVSS Version Base Score Base Severity Vector String 3.1 8 HIGH CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 4.0 8.6 HIGH CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N…
Why it matters
A security flaw matters when an attacker can use it to cross a trust boundary, gain access, run code, bypass authentication, or expose data. The exact risk depends on the affected product, vulnerable versions, exploit conditions, and whether exploitation has been observed. Those details should come from the cited source rather than assumption.
What you should do
Check the vendor or authoritative advisory for affected versions and remediation. Apply the recommended update or mitigation, restart devices or services when required, and prioritize internet-facing or privileged systems. If the source does not report active exploitation, do not treat exploitation as confirmed.