PT-2020-12996 · Rockwell Automation · Factorytalk View Se

Published

2020-01-30

·

Updated

2022-04-25

·

CVE-2020-12028

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions FactoryTalk View SEA remote versions (affected versions not specified) FactoryTalk View SE versions (affected versions not specified)
Description The issue allows an authenticated attacker to interact with data on a remote endpoint due to certain handlers not enforcing appropriate permissions. It is estimated that a significant number of devices may be affected, although the exact number is not provided. There is no information about real-world incidents where this issue was exploited. Technical details about exploitation include the lack of permission enforcement in certain handlers.
Recommendations For FactoryTalk View SEA remote, enable built-in security features and follow guidance in knowledge base articles 109056 and 1126943 to set up IPSec and/or HTTPs. For FactoryTalk View SE, enable built-in security features and follow guidance in knowledge base articles 109056 and 1126943 to set up IPSec and/or HTTPs.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-07165
CVE-2020-12028
ZDI-20-729

Affected Products

Factorytalk View Se