A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted.
History

Tue, 14 Oct 2025 12:30:00 +0000

Type Values Removed Values Added
Description A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted.
Title Rockwell Automation FactoryTalk View Machine Edition Path Traversal
Weaknesses CWE-287
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2025-10-14T18:46:34.339Z

Reserved: 2025-08-15T13:56:26.986Z

Link: CVE-2025-9064

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-14T13:15:39.643

Modified: 2025-10-14T19:36:29.240

Link: CVE-2025-9064

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.