CVE-2020-12028 is a high-severity vulnerability affecting all versions of Rockwell Automation FactoryTalk View SE, where an authenticated attacker can interact with remote endpoint data due to inadequate permission enforcement in certain handlers. With a CVSS score of 8.1, this vulnerability presents a low-complexity network attack vector that can lead to high confidentiality and integrity impacts, though availability is not affected. While not listed in CISA's KEV catalog, a Metasploit module exists for unauthenticated remote code execution, indicating readily available exploit code. Despite this, there is no evidence of active exploitation, and community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:rockwellautomation:factorytalk_view:*:*:*:*:se:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.