CVE-2020-12029
Last modified
CVE-2020-12029 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be able to execute a crafted file on a remote endpoint that may result in remote code execution (RCE). EPSS estimates a 44.98% chance of exploitation in the next 30 days.
Description
All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be able to execute a crafted file on a remote endpoint that may result in remote code execution (RCE). Rockwell Automation recommends applying patch 1126289. Before installing this patch, the patch rollup dated 06 Apr 2020 or later MUST be applied. 1066644 – Patch Roll-up for CPR9 SRx.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Factorytalk View | All versions |
References
- http://packetstormsecurity.com/files/160156/Rockwell-FactoryTalk-View-SE-SCADA-Unauthenticated-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://us-cert.cisa.gov/ics/advisories/icsa-20-170-05Third Party Advisory, US Government Resource
- http://packetstormsecurity.com/files/160156/Rockwell-FactoryTalk-View-SE-SCADA-Unauthenticated-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://us-cert.cisa.gov/ics/advisories/icsa-20-170-05Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-12029?
How severe is CVE-2020-12029?
How do I fix CVE-2020-12029?
Are you affected by CVE-2020-12029?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
