← Vulnerability feed

Vulnerability record · CVE-2020-12029 · published 20 July 2020

CVE-2020-12029: FactoryTalk View SE filename validation flaw enables remote code execution

Rockwellautomation · Factorytalk View

FactoryTalk View SE does not properly validate filenames within a project directory, allowing a crafted file to be executed. The flaw is an improper input validation issue in a widely deployed SCADA HMI product, so successful exploitation can compromise an industrial control environment.

7.8 CVSS 3.1 High EPSS 47% · top 1.2% CWE-20 · Improper input validation
7.8CVSS 3.1 base score, v2 6.8
47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be able to execute a crafted file on a remote endpoint that may result in remote code execution (RCE). Rockwell Automation recommends applying patch 1126289. Before installing this patch, the patch rollup dated 06 Apr 2020 or later MUST be applied. 1066644 – Patch Roll-up for CPR9 SRx.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote code execution in a SCADA product with a public exploit and very high EPSS score, though not in KEV and requiring some user interaction per the vector.

What it is

FactoryTalk View SE does not properly validate filenames within a project directory, allowing a crafted file to be executed. The flaw is an improper input validation issue in a widely deployed SCADA HMI product, so successful exploitation can compromise an industrial control environment.

Impact

An attacker can execute arbitrary code on a remote endpoint, gaining the privileges of the affected process and potentially taking control of the HMI or engineering workstation.

Attack surface

The description states the flaw is reachable by a remote, unauthenticated attacker, but the CVSS vector is local with user interaction required (AV:L/UI:R), so the record is internally inconsistent about how it is reached. No authentication is needed per the description, though some user action appears necessary per the vector.

Exploitation

Not listed in CISA KEV, but EPSS is high at 0.46968 (98.8th percentile) and a public exploit reference exists on Packet Storm, indicating exploit code is available.

What to do

  • Apply Rockwell Automation patch 1126289, first installing the 06 Apr 2020 or later patch rollup (1066644) as required.
  • Restrict network access to FactoryTalk View SE project directories and endpoints to trusted hosts only.
  • Limit which users and processes can write files into project directories.
  • Monitor vendor advisory 1126944 and CISA ICS advisory ICSA-20-170-05 for updated guidance.

Detection

  • Alert on unexpected file creation or modification in FactoryTalk View SE project directories.
  • Monitor for processes spawned by FactoryTalk View SE components that are not part of normal operation.
  • Review endpoint logs for execution of files originating from project directories.
  • Correlate network access to FactoryTalk View SE hosts with file write activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-12029 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-2071Rockwellautomation factorytalk view improper input validation vulnerabilityRockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker t…EPSS 17%9.2CVE-2024-45824Rockwellautomation factorytalk view command injection vulnerabilityCVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command…EPSS 1.3%8.8CVE-2024-4609Rockwellautomation factorytalk view improper input validation vulnerabilityA vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL sta…EPSS 0.65%8.7CVE-2025-9064Rockwellautomation factorytalk view improper authentication vulnerabilityA path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device …EPSS 0.61%8.5CVE-2024-7513Rockwellautomation factorytalk view incorrect permission assignment vulnerabilityCVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permissions…EPSS 1.7%8.5CVE-2024-37369Rockwellautomation factorytalk view incorrect permission assignment vulnerabilityA privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access C…EPSS 0.33%8.2CVE-2024-37368Rockwellautomation factorytalk view improper authentication vulnerabilityA user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with…EPSS 0.50%8.2CVE-2024-37367Rockwellautomation factorytalk view improper authentication vulnerabilityA user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system …EPSS 0.50%

Source: NIST National Vulnerability Database (record CVE-2020-12029), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.