CVE-2025-13036: Rockwell Automation FactoryTalk Historian Site Edition - Authentication Bypass
An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid authentication token.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rockwell Automation FactoryTalk Historian Site Editionto a version that resolves this vulnerability.Fixed in v12.00.00
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13036?
The severity of CVE-2025-13036 is critical with a CVSS score of 9.2.
How does CVE-2025-13036 exploit authentication?
CVE-2025-13036 exploits authentication by allowing attackers to obtain a valid authentication token through repeated requests to the login endpoint.
What systems are affected by CVE-2025-13036?
CVE-2025-13036 affects Rockwell Automation FactoryTalk Historian Site Edition.
How can organizations mitigate CVE-2025-13036?
Organizations can mitigate CVE-2025-13036 by implementing rate limiting on login attempts to prevent brute-force attacks.
When was CVE-2025-13036 published?
CVE-2025-13036 was published on June 16, 2026.