A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted.
History

Tue, 28 Oct 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation factorytalk View
Weaknesses CWE-22
CPEs cpe:2.3:a:rockwellautomation:factorytalk_view:*:*:*:*:machine:*:*:*
Vendors & Products Rockwellautomation factorytalk View
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Mon, 20 Oct 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation factorytalk View Machine Edition
Vendors & Products Rockwellautomation
Rockwellautomation factorytalk View Machine Edition

Wed, 15 Oct 2025 09:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Oct 2025 12:30:00 +0000

Type Values Removed Values Added
Description A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted.
Title Rockwell Automation FactoryTalk View Machine Edition Path Traversal
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published: 2025-10-14T12:22:36.551Z

Updated: 2025-10-14T18:46:34.339Z

Reserved: 2025-08-15T13:56:26.986Z

Link: CVE-2025-9064

cve-icon Vulnrichment

Updated: 2025-10-14T18:46:29.486Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-14T13:15:39.643

Modified: 2025-10-28T15:20:33.767

Link: CVE-2025-9064

cve-icon Redhat

No data.