CISA urges water facilities to secure their Unitronics PLCs
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-6448 | Default Admin Password in Unitronics Vision PLC and HMI (VisiLogic < 9.9.00) Unitronics VisiLogic software before version 9.9.00, which runs on Vision and Samba PLCs and HMIs, ships with a default administrative password that many deployments never change. An unauthenticated attacker with network access to the device can authenticate with these default credentials, requiring no exploit development or user interaction. A successful login grants full administrative control of the PLC/HMI, allowing the attacker to modify configuration and program logic and potentially disrupt the physical process (such as water treatment and distribution) the device controls. Any deployment of the listed Unitronics Vision models (and, per CISA's description, Samba devices) running VisiLogic prior to 9.9.00 is affected, with the greatest risk for units directly exposed to the internet at utilities and small industrial sites. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-11, indicating confirmed exploitation in the wild, and CISA has urged water facilities to secure their Unitronics PLCs. Do: Upgrade to VisiLogic 9.9.00 or later and set a strong, unique administrative password on every Vision/Samba device. Restrict network access to affected devices (firewall or VPN rather than direct internet exposure) and review device logs for unexpected administrative logins. Per the CISA KEV required action, apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | 9.8 | 2% | KEV |
| large~tens of thousands of deployed devices (subset of the vendor-cited installed base of hundreds of thousands of controllers; likely only a low-thousands subset… |
Full article406 words · extracted from helpnetsecurity.com · click to collapse
News that Iran-affiliated attackers have taken over a programmable logic controller (PLC) at a water system facility in Pennsylvania has been followed by a public alert urging other water authorities to immediately secure their own PLCs.

“The cyber threat actors likely accessed the affected device—a Unitronics Vision Series PLC with a Human Machine Interface (HMI)—by exploiting cybersecurity weaknesses, including poor password security and exposure to the internet,” the Cybersecurity and Infrastructure Security Agency (CISA) noted.
The PLC in question has a known default password and uses a known default port (TCP 20256), CISA explained, and urged organizations to:
- Change the default password
- Change the default port used by the PLC (if possible)
- Disconnect the PLC from the open internet or, at least, control and protect remote access to it via firewall, VPN, and multi-factor authentication
- Update the PLC/HMI to the latest software/firmware version provided by Unitronics
Finally, CISA says, organizations should back up the logic and configurations on any Unitronics PLCs, so that “in the event of being hit by ransomware”, they can quickly reset the devices and restore the configurations.
Not the only targeted organizations
Luckily for that water authority’s customers, the threat actors seem to have only been interested in getting their political message across. Also, the compromise was detected immediately, so the authority could quickly switch to manual operations.
The North Texas Municipal Water District was not so lucky, as it has apparently been hit by the ransomware gang Daixin Team and the attack affected their business network and phone system (but not their water, wastewater, and solid waste services).
Daixin Team claims to have stolen sensitive data and encrypted over 300 of NTMWD’s servers.
Critical infrastructure under attack
Cyber attackers (and especially ransomware gangs) targeting organizations in critical infrastructure sectors is nothing new: healthcare organizations, in particular, are under a constant barrage.
Organizations running water and wastewater systems are definitely in a disadvantaged situation, as they often have no IT/OT security team and just a small IT team with limited resources and training to keep systems secure and fight cyber attackers off.
But at least in the US, CISA offers help in the form of free cyber vulnerability scanning (to identify vulnerabilities in internet-accessible assets and internet-exposed services) and cybersecurity services.
UPDATE (December 1, 2023, 04:30 a.m. ET):
The vulnerability – default administrative password on Unitronics Vision Series PLCs and HMIs – has been assigned the following designation: CVE-2023-6448.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/11/30/water-system-secure-plcs/