ZeroHour

Vulnerabilities

12 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-38435
Unitronics Vision PLC – CWE-703:

Unitronics Vision PLC – CWE-703: Improper Check or Handling of Exceptional Conditions may allow denial of service

NVD description · AI analysis pending
7.5<1%
  • unitronics visilogic
CVE-2024-27768
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22:

Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE

NVD description · AI analysis pending
9.8
group max
<1%
  • unitronics unilogic
CVE-2023-6448
Default Admin Password in Unitronics Vision PLC and HMI (VisiLogic < 9.9.00)

Unitronics VisiLogic software before version 9.9.00, which runs on Vision and Samba PLCs and HMIs, ships with a default administrative password that many deployments never change. An unauthenticated attacker with network access to the device can authenticate with these default credentials, requiring no exploit development or user interaction. A successful login grants full administrative control of the PLC/HMI, allowing the attacker to modify configuration and program logic and potentially disrupt the physical process (such as water treatment and distribution) the device controls. Any deployment of the listed Unitronics Vision models (and, per CISA's description, Samba devices) running VisiLogic prior to 9.9.00 is affected, with the greatest risk for units directly exposed to the internet at utilities and small industrial sites. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-11, indicating confirmed exploitation in the wild, and CISA has urged water facilities to secure their Unitronics PLCs.

Do: Upgrade to VisiLogic 9.9.00 or later and set a strong, unique administrative password on every Vision/Samba device. Restrict network access to affected devices (firewall or VPN rather than direct internet exposure) and review device logs for unexpected administrative logins. Per the CISA KEV required action, apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

9.82% KEV
  • Unitronics Vision130 PLC/HMI VisiLogic before 9.9.00
  • Unitronics Vision230 PLC/HMI VisiLogic before 9.9.00
  • Unitronics Vision280 PLC/HMI VisiLogic before 9.9.00
  • +9 more
large~tens of thousands of deployed devices (subset of the vendor-cited installed base of hundreds of thousands of controllers; likely only a low-thousands subset…
CVE-2023-2003
Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded

Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded malicious code in the device's data tables via the PCOM protocol, which can then be retrieved by a client and executed on the device.

NVD description · AI analysis pending
9.8<1%
  • unitronics vision1210 firmware
CVE-2016-4519
Stack-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.30 allows remote attackers to execute arbitrary code via a crafted filename field in a Z

Stack-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.30 allows remote attackers to execute arbitrary code via a crafted filename field in a ZIP archive in a vlp file.

NVD description · AI analysis pending
9.84%
  • unitronics visilogic oplc ide