CVE-2020-12027

MEDIUM

FactoryTalk View SE - Exposure of Sensitive Information via Hostname and File Path Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-12027. Includes Metasploit module exploits/windows/scada/rockwell_factorytalk_rce.

AI-analyzed exploit summary This Metasploit module exploits a chain of vulnerabilities in Rockwell FactoryTalk View SE SCADA to achieve unauthenticated remote code execution. It leverages unauthenticated project copy requests, directory traversal, and a race condition, combined with information leak vulnerabilities.

Description

All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system. A remote, authenticated attacker may be able to leverage this information for reconnaissance efforts. Rockwell Automation recommends enabling built in security features found within FactoryTalk View SE. Users should follow guidance found in knowledge base articles 109056 and 1126943 to set up IPSec and/or HTTPs.

Exploits (1)

metasploit WORKING POC EXCELLENT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/scada/rockwell_factorytalk_rce.rb

This Metasploit module exploits a chain of vulnerabilities in Rockwell FactoryTalk View SE SCADA to achieve unauthenticated remote code execution. It leverages unauthenticated project copy requests, directory traversal, and a race condition, combined with information leak vulnerabilities.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: Rockwell FactoryTalk View SE SCADA (version 11.00.00.230)
No auth needed
Prerequisites: Network access to the target · HTTP server to host payload
devstral-2 · analyzed Mar 05, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-20-170-05

Scores

CVSS v3 4.3
EPSS 0.2353
EPSS Percentile 96.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
rockwellautomation/factorytalk_view
Published Jul 20, 2020
Tracked Since Feb 18, 2026