CVE-2025-9064

A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rockwellautomation:factorytalk_view:*:*:*:*:machine:*:*:*

History

28 Oct 2025, 15:20

Type Values Removed Values Added
CWE CWE-22
CPE cpe:2.3:a:rockwellautomation:factorytalk_view:*:*:*:*:machine:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
First Time Rockwellautomation
Rockwellautomation factorytalk View
References () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1753.html - () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1753.html - Vendor Advisory

14 Oct 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-14 13:15

Updated : 2025-10-28 15:20


NVD link : CVE-2025-9064

Mitre link : CVE-2025-9064

CVE.ORG link : CVE-2025-9064


JSON object : View

Products Affected

rockwellautomation

  • factorytalk_view
CWE
CWE-287

Improper Authentication

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')