Vulnerability record · CVE-2020-12028 · published 20 July 2020
CVE-2020-12028: FactoryTalk View SE remote handlers miss permission checks
Rockwellautomation · Factorytalk View
FactoryTalk View SE remote contains handlers that do not enforce appropriate permissions, allowing an authenticated attacker to interact with data on the remote endpoint. The flaw is a missing or improper access control issue in an industrial HMI/SCADA product, so it matters for environments where that endpoint is reachable and a low-privilege account exists.
Description
In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the remote endpoint since those handlers do not enforce appropriate permissions. Rockwell Automation recommends enabling built in security features found within FactoryTalk View SE. Users should follow guidance found in knowledge base articles 109056 and 1126943 to set up IPSec and/or HTTPs.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Automated analysis
high priorityCVSS 8.1 with high confidentiality and integrity impact, a public exploit reference, and very high EPSS, but exploitation requires valid credentials and there is no KEV listing.
What it is
FactoryTalk View SE remote contains handlers that do not enforce appropriate permissions, allowing an authenticated attacker to interact with data on the remote endpoint. The flaw is a missing or improper access control issue in an industrial HMI/SCADA product, so it matters for environments where that endpoint is reachable and a low-privilege account exists.
Impact
An attacker with valid credentials gains read and write access to data on the remote endpoint, which can affect the integrity and confidentiality of the HMI/SCADA data. The CVSS vector rates confidentiality and integrity impact as high with no availability impact.
Attack surface
Reachable over the network (AV:N) with low privileges required (PR:L) and no user interaction (UI:N). The description states the attacker must be authenticated, so a valid account is needed before the unprotected handlers can be used.
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 0.53 probability (99th percentile), and a public Packet Storm reference is tagged Exploit. That indicates exploit code or a detailed write-up is publicly available, though the record does not confirm active exploitation in the wild.
What to do
- Apply the vendor fix or upgrade per Rockwell Automation advisory and knowledge base article 1126944; patch first.
- Enable FactoryTalk View SE built-in security features as the vendor recommends.
- Restrict network exposure of the remote endpoint and follow knowledge base articles 109056 and 1126943 to deploy IPSec and/or HTTPS.
- Enforce least privilege and review which accounts can reach the remote handlers, since exploitation requires authentication.
- Monitor and segment the SCADA network so the endpoint is not reachable from general IT or untrusted networks.
Detection
- Review logs for authenticated sessions invoking remote handlers outside normal operator behavior or from unexpected hosts.
- Alert on anomalous read/write activity against FactoryTalk View SE remote data endpoints, especially bulk or off-hours access.
- Audit account usage for low-privilege accounts accessing handlers they do not normally use.
- Monitor network flows to the FactoryTalk View SE remote service for connections from non-engineering segments.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/160156/Rockwell-FactoryTalk-View-SE-SCADA-Unauthenticated-Remote-Code-Execution.htm | ExploitThird Party AdvisoryVDB Entry |
| https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1126944 | Vendor Advisory |
| https://us-cert.cisa.gov/ics/advisories/icsa-20-170-05 | Third Party AdvisoryUS Government Resource |
| http://packetstormsecurity.com/files/160156/Rockwell-FactoryTalk-View-SE-SCADA-Unauthenticated-Remote-Code-Execution.htm | ExploitThird Party AdvisoryVDB Entry |
| https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1126944 | Vendor Advisory |
| https://us-cert.cisa.gov/ics/advisories/icsa-20-170-05 | Third Party AdvisoryUS Government Resource |
Track CVE-2020-12028 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-12028), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.