HIGH

CVE-2020-12029

CVSS v3

7.8

HIGH

EPSS Score

24.6%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be able to execute a crafted file on a remote endpoint that may result in remote code execution (RCE). Rockwell Automation recommends applying patch 1126289. Before installing this patch, the patch rollup dated 06 Apr 2020 or later MUST be applied. 1066644 – Patch Roll-up for CPR9 SRx.

Technical details

Published
7/20/2020

Frequently asked questions

What is CVE-2020-12029?

All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be able to execute a crafted file on a remote endpoint that may result in remote code execution (RCE). Rockwell Automation recommends applying patch 1126289. Before installing this patch, the patch rollup dated 06 Apr 2020 or later MUST be applied. 1066644 – Patch Roll-up for CPR9 SRx.

Is CVE-2020-12029 actively exploited?

Active exploitation of CVE-2020-12029 has not been confirmed. The EPSS score is 24.6%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-12029?

CVE-2020-12029 has a CVSS v3 base score of 7.8 (HIGH severity).

Is CVE-2020-12029 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.