Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.
References
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
Configuration 14 (hide)
|
Configuration 15 (hide)
AND |
|
Configuration 16 (hide)
AND |
|
Configuration 17 (hide)
AND |
|
History
21 Nov 2024, 08:43
Type | Values Removed | Values Added |
---|---|---|
References | () https://downloads.unitronicsplc.com/Sites/plc/Technical_Library/Unitronics-Cybersecurity-Advisory-2023-001-CVE-2023-6448.pdf - Vendor Advisory | |
References | () https://downloads.unitronicsplc.com/Sites/plc/Visilogic/Version_Changes-Bug_Reports/VisiLogic%209.9.00%20Version%20changes.pdf - Release Notes | |
References | () https://www.cisa.gov/news-events/alerts/2023/11/28/exploitation-unitronics-plcs-used-water-and-wastewater-systems - Third Party Advisory, US Government Resource | |
References | () https://www.unitronicsplc.com/cyber_security_vision-samba/ - Product |
26 Jun 2024, 19:59
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:unitronics:vision1210_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision230_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision130_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision570_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision120_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision350_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision560_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision290_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision280_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision1040_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision530_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision700_firmware:-:*:*:*:*:*:*:* |
cpe:2.3:o:unitronics:samba_7_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision1210_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision230_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision290_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:unitronics:samba_4.3:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision700_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision570_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision280_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision530_firmware:*:*:*:*:*:*:*:* cpe:2.3:a:unitronics:visilogic:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:samba_3.5_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision350_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:unitronics:samba_7:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision430_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:unitronics:samba_3.5:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision130_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:samba_4.3_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision1040_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision120_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision560_firmware:*:*:*:*:*:*:*:* |
First Time |
Unitronics samba 3.5
Unitronics visilogic Unitronics samba 4.3 Firmware Unitronics samba 7 Unitronics samba 3.5 Firmware Unitronics samba 7 Firmware Unitronics samba 4.3 |
|
References | () https://downloads.unitronicsplc.com/Sites/plc/Technical_Library/Unitronics-Cybersecurity-Advisory-2023-001-CVE-2023-6448.pdf - Vendor Advisory | |
References | () https://downloads.unitronicsplc.com/Sites/plc/Visilogic/Version_Changes-Bug_Reports/VisiLogic%209.9.00%20Version%20changes.pdf - Release Notes | |
References | () https://www.unitronicsplc.com/cyber_security_vision-samba/ - Product |
19 Dec 2023, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
13 Dec 2023, 17:15
Type | Values Removed | Values Added |
---|---|---|
Summary | Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system. |
13 Dec 2023, 15:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
12 Dec 2023, 15:31
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-798 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CPE | cpe:2.3:h:unitronics:vision1040:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision1210:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision560:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision230_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision280_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision290_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision700:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision350:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision120:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision120_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision530:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision350_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision130:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision430_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision290:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision430:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision700_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision570_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision1210_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision530_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision280:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision560_firmware:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision1040_firmware:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision570:-:*:*:*:*:*:*:* cpe:2.3:h:unitronics:vision230:-:*:*:*:*:*:*:* cpe:2.3:o:unitronics:vision130_firmware:-:*:*:*:*:*:*:* |
|
References | () https://www.cisa.gov/news-events/alerts/2023/11/28/exploitation-unitronics-plcs-used-water-and-wastewater-systems - Third Party Advisory, US Government Resource |
05 Dec 2023, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-05 18:15
Updated : 2024-11-21 08:43
NVD link : CVE-2023-6448
Mitre link : CVE-2023-6448
CVE.ORG link : CVE-2023-6448
JSON object : View
Products Affected
unitronics
- vision570_firmware
- vision290
- vision570
- samba_7_firmware
- samba_4.3_firmware
- vision280
- vision230
- vision290_firmware
- vision130
- samba_3.5_firmware
- vision130_firmware
- vision350_firmware
- vision1040
- vision1040_firmware
- samba_4.3
- vision430_firmware
- samba_3.5
- vision430
- vision700_firmware
- vision1210
- vision230_firmware
- vision120_firmware
- vision560
- vision280_firmware
- vision120
- vision1210_firmware
- vision530_firmware
- vision530
- vision350
- visilogic
- vision700
- vision560_firmware
- samba_7