CVE-2023-6448

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/12/2023
Last modified:
27/01/2025

Description

Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:unitronics:vision1210_firmware:*:*:*:*:*:*:*:* 12.38 (excluding)
cpe:2.3:h:unitronics:vision1210:-:*:*:*:*:*:*:*
cpe:2.3:o:unitronics:vision1040_firmware:*:*:*:*:*:*:*:* 12.38 (excluding)
cpe:2.3:h:unitronics:vision1040:-:*:*:*:*:*:*:*
cpe:2.3:o:unitronics:vision700_firmware:*:*:*:*:*:*:*:* 12.38 (excluding)
cpe:2.3:h:unitronics:vision700:-:*:*:*:*:*:*:*
cpe:2.3:o:unitronics:vision570_firmware:*:*:*:*:*:*:*:* 12.38 (excluding)
cpe:2.3:h:unitronics:vision570:-:*:*:*:*:*:*:*
cpe:2.3:o:unitronics:vision560_firmware:*:*:*:*:*:*:*:* 12.38 (excluding)
cpe:2.3:h:unitronics:vision560:-:*:*:*:*:*:*:*
cpe:2.3:o:unitronics:vision430_firmware:*:*:*:*:*:*:*:* 12.38 (excluding)
cpe:2.3:h:unitronics:vision430:-:*:*:*:*:*:*:*
cpe:2.3:o:unitronics:vision350_firmware:*:*:*:*:*:*:*:* 12.38 (excluding)
cpe:2.3:h:unitronics:vision350:-:*:*:*:*:*:*:*
cpe:2.3:o:unitronics:vision130_firmware:*:*:*:*:*:*:*:* 12.38 (excluding)