Authentication Bypass in FactoryTalk View Machine Edition Affecting Rockwell Automation Products
CVE-2025-9063

7HIGH

What is CVE-2025-9063?

A security flaw has been identified in the Web Browser ActiveX control of FactoryTalk View Machine Edition, which can lead to unauthorized access to the PanelView Plus 7 Series B devices. This vulnerability could allow malicious users to bypass authentication mechanisms, granting them control over the device's file system, and potentially enabling access to sensitive information such as diagnostic data and event logs.

Affected Version(s)

PanelView Plus 7 Performance Series B V14.00

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-9063 : Authentication Bypass in FactoryTalk View Machine Edition Affecting Rockwell Automation Products