Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
Configuration 14 (hide)
|
Configuration 15 (hide)
AND |
|
Configuration 16 (hide)
AND |
|
Configuration 17 (hide)
AND |
|
History
21 Nov 2024, 08:43
Type | Values Removed | Values Added |
---|---|---|
References | () https://downloads.unitronicsplc.com/Sites/plc/Technical_Library/Unitronics-Cybersecurity-Advisory-2023-001-CVE-2023-6448.pdf - Vendor Advisory | |
References | () https://downloads.unitronicsplc.com/Sites/plc/Visilogic/Version_Changes-Bug_Reports/VisiLogic%209.9.00%20Version%20changes.pdf - Release Notes | |
References | () https://www.cisa.gov/news-events/alerts/2023/11/28/exploitation-unitronics-plcs-used-water-and-wastewater-systems - Third Party Advisory, US Government Resource | |
References | () https://www.unitronicsplc.com/cyber_security_vision-samba/ - Product |
26 Jun 2024, 19:59
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:unitronics:vision700_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision1040_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision230_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision280_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision120_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision560_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision290_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision350_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision530_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision1210_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision130_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision430_firmware:-:*:*:*:*:*:*:* |
cpe:2.3:o:unitronics:vision700_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision350_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision130_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision1040_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:unitronics:samba_7:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision430_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision290_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision530_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision230_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision570_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:samba_7_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision120_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision1210_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:unitronics:samba_3.5:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:samba_4.3:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:samba_4.3_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:samba_3.5_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision280_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision560_firmware:*:*:*:*:*:*:*:* cpe:2.3:a:unitronics:visilogic:*:*:*:*:*:*:*:* |
First Time |
Unitronics samba 4.3 Firmware
Unitronics samba 7 Unitronics samba 3.5 Unitronics samba 7 Firmware Unitronics samba 4.3 Unitronics samba 3.5 Firmware Unitronics visilogic |
|
References | () https://downloads.unitronicsplc.com/Sites/plc/Technical_Library/Unitronics-Cybersecurity-Advisory-2023-001-CVE-2023-6448.pdf - Vendor Advisory | |
References | () https://downloads.unitronicsplc.com/Sites/plc/Visilogic/Version_Changes-Bug_Reports/VisiLogic%209.9.00%20Version%20changes.pdf - Release Notes | |
References | () https://www.unitronicsplc.com/cyber_security_vision-samba/ - Product |
19 Dec 2023, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
13 Dec 2023, 17:15
Type | Values Removed | Values Added |
---|---|---|
First Time |
Unitronics vision130 Firmware
Unitronics vision1040 Firmware Unitronics vision560 Unitronics vision560 Firmware Unitronics vision230 Firmware Unitronics vision1210 Firmware Unitronics vision290 Unitronics vision120 Firmware Unitronics vision700 Unitronics vision130 Unitronics vision430 Firmware Unitronics vision700 Firmware Unitronics vision280 Firmware Unitronics vision570 Unitronics vision120 Unitronics vision430 Unitronics vision230 Unitronics Unitronics vision1040 Unitronics vision1210 Unitronics vision280 Unitronics vision530 Unitronics vision570 Firmware Unitronics vision350 Unitronics vision290 Firmware Unitronics vision530 Firmware Unitronics vision350 Firmware |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CPE | cpe:2.3:o:unitronics:vision560_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision120:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision130_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision530_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision1210:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision230:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision1040:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision700_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision350_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision120_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision1040_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision350:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision530:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision280:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision570:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision1210_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision430_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision280_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision290_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision130:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision700:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision560:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision570_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision230_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision290:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision430:-:*:*:*:*:*:*:* |
|
Summary | Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system. | |
References |
|
|
References | () https://www.cisa.gov/news-events/alerts/2023/11/28/exploitation-unitronics-plcs-used-water-and-wastewater-systems - Third Party Advisory, US Government Resource | |
CWE | CWE-798 |
05 Dec 2023, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-05 18:15
Updated : 2024-11-21 08:43
NVD link : CVE-2023-6448
Mitre link : CVE-2023-6448
CVE.ORG link : CVE-2023-6448
JSON object : View
Products Affected
unitronics
- vision350_firmware
- samba_7_firmware
- vision530
- vision700
- vision1210
- vision430_firmware
- vision570_firmware
- vision560
- vision290
- vision1040
- vision130_firmware
- samba_3.5
- samba_4.3_firmware
- samba_4.3
- vision230
- vision570
- samba_7
- vision280_firmware
- vision120
- visilogic
- vision350
- vision1040_firmware
- vision430
- vision560_firmware
- vision280
- vision230_firmware
- vision120_firmware
- vision530_firmware
- vision130
- vision700_firmware
- vision1210_firmware
- vision290_firmware
- samba_3.5_firmware