CVE-2020-12029

CRITICAL

Rockwellautomation Factorytalk View - Improper Input Validation

Title source: rule

Description

All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be able to execute a crafted file on a remote endpoint that may result in remote code execution (RCE). Rockwell Automation recommends applying patch 1126289. Before installing this patch, the patch rollup dated 06 Apr 2020 or later MUST be applied. 1066644 – Patch Roll-up for CPR9 SRx.

Exploits (1)

metasploit WORKING POC EXCELLENT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/scada/rockwell_factorytalk_rce.rb

Scores

CVSS v3 9.0
EPSS 0.2462
EPSS Percentile 96.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Details

CWE
CWE-20
Status published
Products (1)
rockwellautomation/factorytalk_view
Published Jul 20, 2020
Tracked Since Feb 18, 2026