CVE-2025-13036
Last modified
CVE-2025-13036 is a critical-severity vulnerability rated 9.2/10 on the CVSS scale. An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid authentication token.. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid authentication token.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Rockwell Automation | FactoryTalk Historian SE | v11 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2025-13036?
How severe is CVE-2025-13036?
How do I fix CVE-2025-13036?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-13030All versions of the package django-mdeditor are vulnerable t…9.8
- CVE-2025-13031The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.1…5.9
- CVE-2025-13032Double fetch in sandbox kernel driver in Avast/AVG Antivirus…7.8
- CVE-2025-13033A vulnerability was identified in the email parsing library …7.5
- CVE-2025-13034When using `CURLOPT_PINNEDPUBLICKEY` option with libcurl or …5.9
- CVE-2025-13035The Code Snippets plugin for WordPress is vulnerable to PHP …8
- CVE-2025-1304The NewsBlogger theme for WordPress is vulnerable to arbitra…8.8
- CVE-2025-13042Inappropriate implementation in V8 in Google Chrome prior to…8.8
- CVE-2025-13044IBM Concert 1.0.0 through 2.2.0 creates temporary files with…6.2
- CVE-2025-13046Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-13047Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-13048The StatCounter – Free Real Time Visitor Stats plugin for Wo…6.4
Are you affected by CVE-2025-13036?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
