CVE-2020-12028

HIGH

FactoryTalk View SE - Authenticated Remote Code Execution via Unrestricted Data Handler

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-12028. Includes Metasploit module exploits/windows/scada/rockwell_factorytalk_rce.

AI-analyzed exploit summary This Metasploit module exploits a chain of vulnerabilities in Rockwell FactoryTalk View SE SCADA to achieve unauthenticated remote code execution. It leverages unauthenticated project copy requests, directory traversal, and a race condition, combined with information leak vulnerabilities.

Description

In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the remote endpoint since those handlers do not enforce appropriate permissions. Rockwell Automation recommends enabling built in security features found within FactoryTalk View SE. Users should follow guidance found in knowledge base articles 109056 and 1126943 to set up IPSec and/or HTTPs.

Exploits (1)

metasploit WORKING POC EXCELLENT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/scada/rockwell_factorytalk_rce.rb

This Metasploit module exploits a chain of vulnerabilities in Rockwell FactoryTalk View SE SCADA to achieve unauthenticated remote code execution. It leverages unauthenticated project copy requests, directory traversal, and a race condition, combined with information leak vulnerabilities.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: Rockwell FactoryTalk View SE SCADA (version 11.00.00.230)
No auth needed
Prerequisites: Network access to the target · HTTP server to host payload
devstral-2 · analyzed Mar 05, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-20-170-05

Scores

CVSS v3 7.3
EPSS 0.2989
EPSS Percentile 96.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Details

CWE
CWE-306 CWE-264
Status published
Products (1)
rockwellautomation/factorytalk_view
Published Jul 20, 2020
Tracked Since Feb 18, 2026