PT-2020-12995 · Rockwell Automation · Rockwell Automation Factorytalk View Se+1

Published

2020-01-30

·

Updated

2021-09-23

·

CVE-2020-12027

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Rockwell Automation FactoryTalk View SE (affected versions not specified) Rockwell Automation Studio 5000 (affected versions not specified)
Description The issue allows a remote, authenticated attacker to potentially gather sensitive information about the system, including hostnames and file paths for certain files. This could be leveraged for reconnaissance efforts. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations For Rockwell Automation FactoryTalk View SE, enable built-in security features, and follow the guidance in knowledge base articles 109056 and 1126943 to set up IPSec and/or HTTPS. For Rockwell Automation Studio 5000, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-16193
CVE-2020-12027
ZDI-20-727
ZDI-20-728
ZDI-20-732

Affected Products

Rockwell Automation Factorytalk View Se
Rockwell Automation Studio 5000