peter bassill · operator
$ cve CVE-2020-12029 JSON

CVE-2020-12029

9.0
CRITICAL · CVSS 3.1 · EPSS 47% (pctl 99)

Patch early

EPSS 47% — above the 10% action threshold.

Description

All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be able to execute a crafted file on a remote endpoint that may result in remote code execution (RCE). Rockwell Automation recommends applying patch 1126289. Before installing this patch, the patch rollup dated 06 Apr 2020 or later MUST be applied. 1066644 – Patch Roll-up for CPR9 SRx.

Scoring

CVSS9.0 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
EPSS46.97% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2020-07-20
Last modified2026-06-17

Affected (1)

VendorProduct
rockwellautomationfactorytalk view

References

→ the Explorer  ·  watch your stack  ·  NVD