CVE-2025-9063
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-14

Last updated on: 2025-10-28

Assigner: Rockwell Automation

Description
An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exploitation of this vulnerability allows unauthorized access to the PanelView Plus 7 Series B, including access to the file system, retrieval of diagnostic information, event logs, and more.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-14
Last Modified
2025-10-28
Generated
2026-06-16
AI Q&A
2025-10-14
EPSS Evaluated
2026-06-14
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
rockwellautomation factorytalk_view to 15.0 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-NVD-CWE-noinfo
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2025-9063 is an authentication bypass vulnerability in the FactoryTalk View Machine Edition Web Browser ActiveX control used in PanelView Plus 7 Performance Series B devices. This flaw allows an attacker to bypass authentication controls and gain unauthorized access to the device, including its file system, diagnostic information, event logs, and other sensitive data. [1]

Impact Analysis

Exploitation of this vulnerability can lead to unauthorized access to critical system components of the PanelView Plus 7 Series B device. An attacker could retrieve sensitive diagnostic information, access event logs, and manipulate the file system, potentially compromising the integrity and confidentiality of the system and disrupting its normal operation. [1]

Mitigation Strategies

To mitigate CVE-2025-9063, immediately upgrade the PanelView Plus 7 Performance Series B firmware to version V14.103 (package 9701M-VWSTNMT). If upgrading is not possible, remove the FactoryTalk View Machine Edition Web Browser ActiveX control to prevent unauthorized access. Additionally, follow Rockwell Automation's security best practices and subscribe to their security alerts for ongoing support. [1]

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-9063. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart