CVE-2025-9064: Rockwell Automation FactoryTalk View Machine Edition Path Traversal
A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9064?
CVE-2025-9064 is classified as a critical vulnerability due to the risk of unauthorized file deletion within the panel's operating system.
How do I fix CVE-2025-9064?
To fix CVE-2025-9064, update Rockwell Automation FactoryTalk View Machine Edition to the latest version that addresses this security issue.
Who is affected by CVE-2025-9064?
CVE-2025-9064 affects users of Rockwell Automation's FactoryTalk View Machine Edition on networks where attackers may gain access.
What can attackers do with CVE-2025-9064?
Attackers exploiting CVE-2025-9064 can delete any file within the panels operating system if they are on the same network.
Is authentication required to exploit CVE-2025-9064?
No, CVE-2025-9064 can be exploited by unauthenticated attackers, making it particularly dangerous.