← Vulnerability feed

Vulnerability record · CVE-2020-12027 · published 20 July 2020

CVE-2020-12027: FactoryTalk View SE information disclosure of hostnames and file paths

Rockwellautomation · Factorytalk View

All versions of Rockwell Automation FactoryTalk View SE disclose hostnames and file paths for certain files within the system. The flaw is an information exposure issue that leaks internal system details useful for reconnaissance. It matters because that data can help an attacker plan follow-on activity against an industrial control environment.

4.3 CVSS 3.1 Medium EPSS 53% · top 1.1% CWE-200 · Information exposure
4.3CVSS 3.1 base score, v2 4.0
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system. A remote, authenticated attacker may be able to leverage this information for reconnaissance efforts. Rockwell Automation recommends enabling built in security features found within FactoryTalk View SE. Users should follow guidance found in knowledge base articles 109056 and 1126943 to set up IPSec and/or HTTPs.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

medium priorityCVSS 3.1 base score is 4.3 (Medium) with limited confidentiality impact only, though EPSS is high and the target is an ICS product.

What it is

All versions of Rockwell Automation FactoryTalk View SE disclose hostnames and file paths for certain files within the system. The flaw is an information exposure issue that leaks internal system details useful for reconnaissance. It matters because that data can help an attacker plan follow-on activity against an industrial control environment.

Impact

An attacker gains internal hostnames and file paths, improving reconnaissance and targeting of later attacks. No direct code execution or data modification is provided by this flaw alone.

Attack surface

Reachable over the network (AV:N) by an authenticated attacker with low privileges (PR:L), with no user interaction (UI:N). The description states a remote, authenticated attacker can leverage the disclosed information.

Exploitation

Not listed in CISA KEV and no ransomware use documented. EPSS is high (0.53024, 98.9th percentile), but the references include a third-party advisory titled for unauthenticated remote code execution, which is not the flaw described here; treat that as context, not confirmation of exploitation of this CVE.

What to do

  • Apply the vendor guidance in Rockwell Automation knowledge base articles 109056 and 1126943 and any available FactoryTalk View SE updates.
  • Enable the built-in security features within FactoryTalk View SE as recommended by the vendor.
  • Set up IPSec and/or HTTPS as directed by the vendor to protect traffic and limit exposure.
  • Restrict network access to FactoryTalk View SE systems and enforce least privilege for authenticated accounts.
  • Monitor for reconnaissance activity against these systems given the information disclosure.

Detection

  • Review access logs for authenticated users querying or enumerating hostnames and file paths.
  • Alert on unusual enumeration or discovery behavior from low-privilege accounts against FactoryTalk View SE.
  • Correlate disclosed path and hostname strings appearing in outbound or lateral traffic.
  • Monitor for scanning or reconnaissance patterns targeting FactoryTalk View SE endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-12027 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-2071Rockwellautomation factorytalk view improper input validation vulnerabilityRockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker t…EPSS 17%9.2CVE-2024-45824Rockwellautomation factorytalk view command injection vulnerabilityCVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command…EPSS 1.3%8.8CVE-2024-4609Rockwellautomation factorytalk view improper input validation vulnerabilityA vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL sta…EPSS 0.65%8.7CVE-2025-9064Rockwellautomation factorytalk view improper authentication vulnerabilityA path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device …EPSS 0.61%8.5CVE-2024-7513Rockwellautomation factorytalk view incorrect permission assignment vulnerabilityCVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permissions…EPSS 1.7%8.5CVE-2024-37369Rockwellautomation factorytalk view incorrect permission assignment vulnerabilityA privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access C…EPSS 0.33%8.2CVE-2024-37368Rockwellautomation factorytalk view improper authentication vulnerabilityA user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with…EPSS 0.50%8.2CVE-2024-37367Rockwellautomation factorytalk view improper authentication vulnerabilityA user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system …EPSS 0.50%

Source: NIST National Vulnerability Database (record CVE-2020-12027), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.