Vulnerability record · CVE-2020-12027 · published 20 July 2020
CVE-2020-12027: FactoryTalk View SE information disclosure of hostnames and file paths
Rockwellautomation · Factorytalk View
All versions of Rockwell Automation FactoryTalk View SE disclose hostnames and file paths for certain files within the system. The flaw is an information exposure issue that leaks internal system details useful for reconnaissance. It matters because that data can help an attacker plan follow-on activity against an industrial control environment.
Description
All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system. A remote, authenticated attacker may be able to leverage this information for reconnaissance efforts. Rockwell Automation recommends enabling built in security features found within FactoryTalk View SE. Users should follow guidance found in knowledge base articles 109056 and 1126943 to set up IPSec and/or HTTPs.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Automated analysis
medium priorityCVSS 3.1 base score is 4.3 (Medium) with limited confidentiality impact only, though EPSS is high and the target is an ICS product.
What it is
All versions of Rockwell Automation FactoryTalk View SE disclose hostnames and file paths for certain files within the system. The flaw is an information exposure issue that leaks internal system details useful for reconnaissance. It matters because that data can help an attacker plan follow-on activity against an industrial control environment.
Impact
An attacker gains internal hostnames and file paths, improving reconnaissance and targeting of later attacks. No direct code execution or data modification is provided by this flaw alone.
Attack surface
Reachable over the network (AV:N) by an authenticated attacker with low privileges (PR:L), with no user interaction (UI:N). The description states a remote, authenticated attacker can leverage the disclosed information.
Exploitation
Not listed in CISA KEV and no ransomware use documented. EPSS is high (0.53024, 98.9th percentile), but the references include a third-party advisory titled for unauthenticated remote code execution, which is not the flaw described here; treat that as context, not confirmation of exploitation of this CVE.
What to do
- Apply the vendor guidance in Rockwell Automation knowledge base articles 109056 and 1126943 and any available FactoryTalk View SE updates.
- Enable the built-in security features within FactoryTalk View SE as recommended by the vendor.
- Set up IPSec and/or HTTPS as directed by the vendor to protect traffic and limit exposure.
- Restrict network access to FactoryTalk View SE systems and enforce least privilege for authenticated accounts.
- Monitor for reconnaissance activity against these systems given the information disclosure.
Detection
- Review access logs for authenticated users querying or enumerating hostnames and file paths.
- Alert on unusual enumeration or discovery behavior from low-privilege accounts against FactoryTalk View SE.
- Correlate disclosed path and hostname strings appearing in outbound or lateral traffic.
- Monitor for scanning or reconnaissance patterns targeting FactoryTalk View SE endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/160156/Rockwell-FactoryTalk-View-SE-SCADA-Unauthenticated-Remote-Code-Execution.htm | Third Party AdvisoryVDB Entry |
| https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1126944 | Vendor Advisory |
| https://us-cert.cisa.gov/ics/advisories/icsa-20-170-05 | Third Party AdvisoryUS Government Resource |
| http://packetstormsecurity.com/files/160156/Rockwell-FactoryTalk-View-SE-SCADA-Unauthenticated-Remote-Code-Execution.htm | Third Party AdvisoryVDB Entry |
| https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1126944 | Vendor Advisory |
| https://us-cert.cisa.gov/ics/advisories/icsa-20-170-05 | Third Party AdvisoryUS Government Resource |
Track CVE-2020-12027 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-12027), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.