ZeroHour

CVE-2023-6448

KEVlarge

Default Admin Password in Unitronics Vision PLC and HMI (VisiLogic < 9.9.00)

CISA: Unitronics Vision PLC and HMI Insecure Default Password Vulnerability

CVSS 3.1
9.8 critical
EPSS
2%p80
Published
()
KEV added
AI analysis

Unitronics VisiLogic software before version 9.9.00, which runs on Vision and Samba PLCs and HMIs, ships with a default administrative password that many deployments never change. An unauthenticated attacker with network access to the device can authenticate with these default credentials, requiring no exploit development or user interaction. A successful login grants full administrative control of the PLC/HMI, allowing the attacker to modify configuration and program logic and potentially disrupt the physical process (such as water treatment and distribution) the device controls. Any deployment of the listed Unitronics Vision models (and, per CISA's description, Samba devices) running VisiLogic prior to 9.9.00 is affected, with the greatest risk for units directly exposed to the internet at utilities and small industrial sites. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-11, indicating confirmed exploitation in the wild, and CISA has urged water facilities to secure their Unitronics PLCs.

What to do: Upgrade to VisiLogic 9.9.00 or later and set a strong, unique administrative password on every Vision/Samba device. Restrict network access to affected devices (firewall or VPN rather than direct internet exposure) and review device logs for unexpected administrative logins. Per the CISA KEV required action, apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Affected
Unitronics Vision130 PLC/HMIVisiLogic before 9.9.00
Unitronics Vision230 PLC/HMIVisiLogic before 9.9.00
Unitronics Vision280 PLC/HMIVisiLogic before 9.9.00
Unitronics Vision290 PLC/HMIVisiLogic before 9.9.00
Unitronics Vision350 PLC/HMIVisiLogic before 9.9.00
Unitronics Vision430 PLC/HMIVisiLogic before 9.9.00
Unitronics Vision530 PLC/HMIVisiLogic before 9.9.00
Unitronics Vision560 PLC/HMIVisiLogic before 9.9.00
Unitronics Vision570 PLC/HMIVisiLogic before 9.9.00
Unitronics Vision700 PLC/HMIVisiLogic before 9.9.00
Unitronics Vision1040 PLC/HMIVisiLogic before 9.9.00
Unitronics Vision1210 PLC/HMIVisiLogic before 9.9.00
Estimated exposure
large~tens of thousands of deployed devices (subset of the vendor-cited installed base of hundreds of thousands of controllers; likely only a low-thousands subset… — Unitronics has publicly cited hundreds of thousands of its controllers installed worldwide, concentrated in water/wastewater and other small-utility and industrial settings, while internet-wide scans typically show only a few thousand…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.

CISA Known Exploited Vulnerability
Affected
Unitronics Vision PLC and HMI
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
unitronics
Products
vision1210 firmware, vision1040 firmware, vision700 firmware, vision570 firmware, vision560 firmware, vision430 firmware, vision350 firmware, vision130 firmware, vision230 firmware, vision280 firmware, vision290 firmware, vision530 firmware
Weakness
CWE-1188, CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news