CVE-2023-6448
Description
Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.
Summary dbcve.org
Unitronics VisiLogic software before version 9.9.00 used on Vision and Samba PLCs and HMIs contains a default administrative password. Unauthenticated remote attackers with network access can leverage this hardcoded credential to gain full administrative control of the affected industrial controller.
Mitigation
Immediately change the default administrative password on all affected Unitronics Vision and Samba PLCs/HMIs, restrict network exposure by placing devices behind firewalls or VPNs, and upgrade VisiLogic to version 9.9.00 or later.