---
id: CVE-2025-9063
title: >-
  An authentication bypass security issue exists within FactoryTalk View Machine
  Edition  Web Browser ActiveX control
summary: >-
  An authentication bypass security issue exists within FactoryTalk View Machine
  Edition  Web Browser ActiveX control. Exploitation of this vulnerability
  allows unauthorized access to the PanelView Plus 7 Series B, including access
  to the …
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-287
vendor: rockwellautomation
product: factorytalk_view
affected:
  - factorytalk_view <= 15.0
published: '2025-10-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9063'
references:
  - url: >-
      https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1753.html
    label: PSIRT@rockwellautomation.com
tags:
  - nvd
epss: 0.00385
epssPercentile: 0.30361
ingestedAt: '2026-10-08T11:31:27.378Z'
---

## Overview

An authentication bypass security issue exists within FactoryTalk View Machine Edition  Web Browser ActiveX control. Exploitation of this vulnerability allows unauthorized access to the PanelView Plus 7 Series B, including access to the file system, retrieval of diagnostic information, event logs, and more.

## Affected

- `factorytalk_view <= 15.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
