CVE-2025-36539
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to obtain a valid authentication token, perform a denial of service, or crash the system. The following ve...
Affects 0 products across 2 vendors.
CVE-2025-36539 affects AVEVA PI Data Archive products, allowing an authenticated user to shut down certain subsystems via an uncaught exception, leading to a denial of service.
BSID: BS-2025-GLOBAL-255430-M • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2025-36539?
What is the CVSS score for CVE-2025-36539?
Is CVE-2025-36539 actively exploited?
How do I remediate CVE-2025-36539?
What systems are affected by CVE-2025-36539?
| CVE ID | CVE-2025-36539 |
|---|---|
| BSID | BS-2025-GLOBAL-255430-M BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| Published | 2026-06-18 |
| Last Modified | 2026-06-18 |
| ICS Relevance | 65% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to obtain a valid authentication token, perform a denial of service, or crash the system. The following versions of Rockwell Automation FactoryTalk Historian Site Edition are affected: FactoryTalk Historian SE 11 (CVE-2025-13036) FactoryTalk Historian SE <=11.00 (CVE-2025-44019) FactoryTalk Historian SE <=11.00 (CVE-2025-36539) CVSS Vendor Equipment Vulnerabilities v3 7.7 Rockwell Automation Rockwell Autom
Source: NIST NVD / MITRE CVE Database
An authenticated user can exploit an uncaught exception in the AVEVA PI Data Archive software to cause a denial of service by shutting down critical subsystems.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Aveva | — | — |
| Rockwell Automation | — | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 1da53a5fb3bea3591ba666c691f6f9e81f82852b291a06c7f1ea8d2a24bca85f35aaedff42ce43cd32cb0636fdb28c297fa2c7f35bd8dce3672c422390808a6b |
ICS/OT Vulnerability Intelligence for Your Environment
BreachSpider monitors 353,228 CVEs across ICS/OT vendors. SAGE-enriched alerts with virtual patches, NERC-CIP mapping, and PSIRT contacts delivered to your SIEM in minutes.
Join free →