HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2025-9064

CVSS 8.7v4.0pub. 2025-10-14upd. 2025-10-28

A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Rockwellautomation Factorytalk View

    APP
    Rockwellautomation
    ≤ 15.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Path TraversalAuth Bypass
CWE
References

Related vulnerabilities

CVE-2024-45824CRITICAL9.2PL ✓same product

RCE w Rockwell Automation FactoryTalk View — łańcuch path traversal, command injection i XSS

CVE-2023-2071CRITICAL9.8PL ✓same product

RCE bez uwierzytelnienia w Rockwell Automation FactoryTalk View na PanelView Plus

CVE-2020-12029CRITICAL9.0PL ✓same product

RCE w Rockwell Automation FactoryTalk View SE — brak walidacji nazw plików

CVE-2025-9063HIGH7.0same product

An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX co...

CVE-2024-37365HIGH7.0same product

A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save p...