---
id: CVE-2025-9064
title: >-
  A path traversal security issue exists within FactoryTalk View Machine
  Edition, allowing unauthenticated attackers on the same network as the device
  to delete any file within the panels operating system
summary: >-
  A path traversal security issue exists within FactoryTalk View Machine
  Edition, allowing unauthenticated attackers on the same network as the device
  to delete any file within the panels operating system. Exploitation of this
  vulnerabilit…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-287
  - CWE-22
vendor: rockwellautomation
product: factorytalk_view
affected:
  - factorytalk_view <= 15.0
published: '2025-10-14'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T12:10:00.217'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-9064'
references:
  - url: >-
      https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1753.html
    label: PSIRT@rockwellautomation.com
tags:
  - nvd
epss: 0.00607
epssPercentile: 0.47404
ingestedAt: '2026-10-08T11:31:27.379Z'
---

## Overview

A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted.

## Affected

- `factorytalk_view <= 15.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
