ics-otregulatorNewsThe Broadside1 min read

Rockwell Historian ME Hit by RCE and DoS Bugs

The RCE scores 8.6, the DoS 4.8, but both sit at the network-adjacent attack surface, and the affected sectors span chemical, manufacturing, food, healthcare, and water.


TL;DR

CISA and Rockwell Automation disclosed two vulnerabilities in Historian ME Series B 5.202 and Series C 7.101. CVE-2025-12768 is an out-of-bounds write that allows a low-privilege authenticated attacker on an adjacent network to achieve remote code execution (CVSS 8.6). CVE-2026-12661 is a stack-based buffer overflow that lets a network-adjacent authenticated attacker crash the device via crafted web-interface requests (CVSS 4.8). The advisory lists corrected versions but doesn't specify version numbers or a patch timeline. Affected sectors include chemical, critical manufacturing, food and agriculture, healthcare, and water and wastewater systems worldwide.

The more dangerous of the two is CVE-2025-12768, an out-of-bounds write that gives an attacker with low-level authentication remote code execution on the affected device. The attack vector is network-adjacent, not internet-facing by default, but close enough that an adversary who's already on the OT network or has compromised an engineering workstation in the same segment can reach it.

CVE-2026-12661 is a denial-of-service bug: a stack-based buffer overflow triggered by crafted requests to the web interface. It requires authentication, and the CVSS vectors specify high privileges (PR:H). The practical effect is a device crash that leaves the historian unresponsive. For operators relying on Historian ME for process data visibility, that's a gap in situational awareness until the device is recovered.

The advisory says corrected versions exist but doesn't name them. For Series B 5.202 and Series C 7.101, the only concrete guidance is Rockwell's standard security best practices, minimize network exposure, isolate control system networks behind firewalls, use VPNs for remote access. CISA's own recommended practices echo the same. No workaround details are offered for either CVE, and no public exploitation has been reported to CISA as of the September 1 initial publication.

Rockwell disclosed both vulnerabilities to CISA. The advisory covers deployments worldwide.


Published ·Deep Fathom