CVE-2020-12029
9.0
CRITICAL · CVSS 3.1 · EPSS 47% (pctl 99)
Patch early
EPSS 47% — above the 10% action threshold.
Description
All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be able to execute a crafted file on a remote endpoint that may result in remote code execution (RCE). Rockwell Automation recommends applying patch 1126289. Before installing this patch, the patch rollup dated 06 Apr 2020 or later MUST be applied. 1066644 – Patch Roll-up for CPR9 SRx.
Scoring
| CVSS | 9.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
| EPSS | 46.97% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-07-20 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| rockwellautomation | factorytalk view |
References
- http://packetstormsecurity.com/files/160156/Rockwell-FactoryTalk-View-SE-SCADA-Unauthenticated-Remote-Code-Execution.html
- https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1126944
- https://us-cert.cisa.gov/ics/advisories/icsa-20-170-05
- http://packetstormsecurity.com/files/160156/Rockwell-FactoryTalk-View-SE-SCADA-Unauthenticated-Remote-Code-Execution.html
- https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1126944
- https://us-cert.cisa.gov/ics/advisories/icsa-20-170-05
→ the Explorer · watch your stack · NVD