Vulnerability record · CVE-2020-12029 · published 20 July 2020
CVE-2020-12029: FactoryTalk View SE filename validation flaw enables remote code execution
Rockwellautomation · Factorytalk View
FactoryTalk View SE does not properly validate filenames within a project directory, allowing a crafted file to be executed. The flaw is an improper input validation issue in a widely deployed SCADA HMI product, so successful exploitation can compromise an industrial control environment.
Description
All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be able to execute a crafted file on a remote endpoint that may result in remote code execution (RCE). Rockwell Automation recommends applying patch 1126289. Before installing this patch, the patch rollup dated 06 Apr 2020 or later MUST be applied. 1066644 – Patch Roll-up for CPR9 SRx.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote code execution in a SCADA product with a public exploit and very high EPSS score, though not in KEV and requiring some user interaction per the vector.
What it is
FactoryTalk View SE does not properly validate filenames within a project directory, allowing a crafted file to be executed. The flaw is an improper input validation issue in a widely deployed SCADA HMI product, so successful exploitation can compromise an industrial control environment.
Impact
An attacker can execute arbitrary code on a remote endpoint, gaining the privileges of the affected process and potentially taking control of the HMI or engineering workstation.
Attack surface
The description states the flaw is reachable by a remote, unauthenticated attacker, but the CVSS vector is local with user interaction required (AV:L/UI:R), so the record is internally inconsistent about how it is reached. No authentication is needed per the description, though some user action appears necessary per the vector.
Exploitation
Not listed in CISA KEV, but EPSS is high at 0.46968 (98.8th percentile) and a public exploit reference exists on Packet Storm, indicating exploit code is available.
What to do
- Apply Rockwell Automation patch 1126289, first installing the 06 Apr 2020 or later patch rollup (1066644) as required.
- Restrict network access to FactoryTalk View SE project directories and endpoints to trusted hosts only.
- Limit which users and processes can write files into project directories.
- Monitor vendor advisory 1126944 and CISA ICS advisory ICSA-20-170-05 for updated guidance.
Detection
- Alert on unexpected file creation or modification in FactoryTalk View SE project directories.
- Monitor for processes spawned by FactoryTalk View SE components that are not part of normal operation.
- Review endpoint logs for execution of files originating from project directories.
- Correlate network access to FactoryTalk View SE hosts with file write activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/160156/Rockwell-FactoryTalk-View-SE-SCADA-Unauthenticated-Remote-Code-Execution.htm | ExploitThird Party AdvisoryVDB Entry |
| https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1126944 | Vendor Advisory |
| https://us-cert.cisa.gov/ics/advisories/icsa-20-170-05 | Third Party AdvisoryUS Government Resource |
| http://packetstormsecurity.com/files/160156/Rockwell-FactoryTalk-View-SE-SCADA-Unauthenticated-Remote-Code-Execution.htm | ExploitThird Party AdvisoryVDB Entry |
| https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1126944 | Vendor Advisory |
| https://us-cert.cisa.gov/ics/advisories/icsa-20-170-05 | Third Party AdvisoryUS Government Resource |
Track CVE-2020-12029 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-12029), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.