Executive brief
Unitronics Vision and Samba series PLCs and HMIs utilize an insecure default administrative password. An unauthenticated remote attacker with network access can exploit this to gain full administrative control and execute commands on the vulnerable system.
Affected products
- Unitronics Vision PLC VisiLogic before 9.9.00
- Unitronics Samba PLC VisiLogic before 9.9.00
- Unitronics Vision HMI VisiLogic before 9.9.00
- Unitronics Samba HMI VisiLogic before 9.9.00
Timeline
- 2023-11-28: advisory: CISA alert regarding exploitation in water and wastewater systems
- 2023-12-11: disclosed: CVE published and added to CISA KEV catalog
- 2023-12-11: kev added