news.mlab.sh
Back to the feed
vulnerability

Rockwell Automation Historian ME

HighCVSS 8.6
Summary

Rockwell Automation has disclosed vulnerabilities in its FactoryTalk® Historian Machine Edition software, specifically Series B 5.202 and Series C 7.101. An attacker with low-level authentication could exploit these flaws to achieve remote code execution, potentially causing device crashes and unresponsiveness. CISA recommends minimizing network exposure and isolating control systems from business networks.

Rockwell Automation has issued a security advisory regarding vulnerabilities within its FactoryTalk® Historian Machine Edition software. Specifically, versions 5.202 (Series B) and 7.101 (Series C) are affected. An attacker possessing low-level authentication credentials could exploit these vulnerabilities to execute arbitrary code on the device. This could lead to denial-of-service conditions and device crashes. The vulnerabilities are linked to CWE-787 (Out-of-bounds Write) and CWE-121 (Stack-based Buffer Overflow). CISA recommends that organizations take proactive measures to mitigate the risk, including minimizing network exposure and isolating control systems from business networks. When remote access is necessary, utilize secure methods like VPNs, while recognizing that VPNs themselves can have vulnerabilities. Rockwell Automation has reported these vulnerabilities to CISA. Organizations should review and implement Rockwell Automation’s security best practices, accessible at https://support.rockwellautomation.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight and https://www.rockwellautomation.com/en-us/company/about-us/contact-us.html. For further guidance, CISA provides a section for control systems security recommended practices on the ICS webpage at cisa.gov/ics, and a technical information paper, ICS-TIP-12-146-01B--Targeted Cyber Intrusion Detection and Mitigation Strategies, is also available.

Read the full article at CISA Advisories