Status: UPDATED | Advisory ID: CVE-2025-13036
| CVE | CVE-2025-13036 |
| CVSS Score / Version | 9.2 (Critical) / CVSS v4.0 |
| Updated | 2026-09-30 |
| Affected products | Rockwell Automation FactoryTalk Historian SE |
| Classified as | CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Rockwell Automation | FactoryTalk Historian SE |
| Subsystems | General OT |
| Sectors | Multiple |
An authentication
bypass security issue exists within FactoryTalk Historian Site Edition. By
continually sending requests to the login endpoint, an attacker may obtain a
valid authentication token. (NVD)
Monitor Rockwell Automation's web page for any future patch releases.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2025-13036 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2025-13036 |