Junglewise Threat Intelligence

CVE-2023-6448: Unitronics Vision PLC and HMI Insecure Default Password Vulnerability

CVE-2023-6448 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2023-12-11

Executive brief

Unitronics Vision and Samba series PLCs and HMIs utilize an insecure default administrative password. An unauthenticated remote attacker with network access can exploit this to gain full administrative control and execute commands on the vulnerable system.

Affected products

  • Unitronics Vision PLC VisiLogic before 9.9.00
  • Unitronics Samba PLC VisiLogic before 9.9.00
  • Unitronics Vision HMI VisiLogic before 9.9.00
  • Unitronics Samba HMI VisiLogic before 9.9.00

Timeline

  • 2023-11-28: advisory: CISA alert regarding exploitation in water and wastewater systems
  • 2023-12-11: disclosed: CVE published and added to CISA KEV catalog
  • 2023-12-11: kev added