Vulnerability Description
Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Unitronics | Vision1210 Firmware | < 12.38 |
| Unitronics | Vision1210 | - |
| Unitronics | Vision1040 Firmware | < 12.38 |
| Unitronics | Vision1040 | - |
| Unitronics | Vision700 Firmware | < 12.38 |
| Unitronics | Vision700 | - |
| Unitronics | Vision570 Firmware | < 12.38 |
| Unitronics | Vision570 | - |
| Unitronics | Vision560 Firmware | < 12.38 |
| Unitronics | Vision560 | - |
| Unitronics | Vision430 Firmware | < 12.38 |
| Unitronics | Vision430 | - |
| Unitronics | Vision350 Firmware | < 12.38 |
| Unitronics | Vision350 | - |
| Unitronics | Vision130 Firmware | < 12.38 |
| Unitronics | Vision130 | - |
| Unitronics | Vision230 Firmware | < 12.38 |
| Unitronics | Vision230 | - |
| Unitronics | Vision280 Firmware | < 12.38 |
| Unitronics | Vision280 | - |
Related Weaknesses (CWE)
References
- https://downloads.unitronicsplc.com/Sites/plc/Technical_Library/Unitronics-CyberVendor Advisory
- https://downloads.unitronicsplc.com/Sites/plc/Visilogic/Version_Changes-Bug_RepoRelease Notes
- https://www.cisa.gov/news-events/alerts/2023/11/28/exploitation-unitronics-plcs-Third Party AdvisoryUS Government Resource
- https://www.unitronicsplc.com/cyber_security_vision-samba/Product
- https://downloads.unitronicsplc.com/Sites/plc/Technical_Library/Unitronics-CyberVendor Advisory
- https://downloads.unitronicsplc.com/Sites/plc/Visilogic/Version_Changes-Bug_RepoRelease Notes
- https://www.cisa.gov/news-events/alerts/2023/11/28/exploitation-unitronics-plcs-Third Party AdvisoryUS Government Resource
- https://www.unitronicsplc.com/cyber_security_vision-samba/Product
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-US Government Resource
FAQ
What is CVE-2023-6448?
CVE-2023-6448 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative cont...
How severe is CVE-2023-6448?
CVE-2023-6448 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-6448?
Check the references section above for vendor advisories and patch information. Affected products include: Unitronics Vision1210 Firmware, Unitronics Vision1210, Unitronics Vision1040 Firmware, Unitronics Vision1040, Unitronics Vision700 Firmware.