CRITICAL

CVE-2023-6448

Unitronics Vision1210 Firmware 2023-12-05 CVSS v3.1
CVSS
9.8
KEV

Description

Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.

Summary dbcve.org

Unitronics VisiLogic software before version 9.9.00 used on Vision and Samba PLCs and HMIs contains a default administrative password. Unauthenticated remote attackers with network access can leverage this hardcoded credential to gain full administrative control of the affected industrial controller.

Mitigation

Immediately change the default administrative password on all affected Unitronics Vision and Samba PLCs/HMIs, restrict network exposure by placing devices behind firewalls or VPNs, and upgrade VisiLogic to version 9.9.00 or later.

Weakness (CWE)

CWE-1188
CWE-798 Hard-coded Credentials

EPSS Score

2.07%
Probability of exploitation in next 30 days
80.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE