CVE-2025-9064

CRITICAL

FactoryTalk View Machine Edition - Path Traversal

Title source: llm
STIX 2.1

Description

A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted.

Scores

CVSS v3 9.1
EPSS 0.0049
EPSS Percentile 65.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22 CWE-287
Status published
Products (1)
rockwellautomation/factorytalk_view < 15.0
Published Oct 14, 2025
Tracked Since Feb 18, 2026