PT-2023-7495 · Unitronics · Unitronics Vision Series Plcs+2

Publicado

2023-12-05

·

Atualizado

2024-06-26

·

CVE-2023-6448

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Unitronics VisiLogic versions prior to 9.9.00 Unitronics Vision Series PLCs and HMIs (affected versions not specified)
Description The issue is related to the use of default administrative passwords in Unitronics Vision Series PLCs and HMIs. An unauthenticated attacker with network access can take administrative control of a vulnerable system. The vulnerability has been exploited in real-world attacks, including an incident where hackers attacked a US water facility.
Recommendations For Unitronics VisiLogic versions prior to 9.9.00, update to version 9.9.00 or later to resolve the issue. For Unitronics Vision Series PLCs and HMIs, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider changing the default administrative password to a strong and unique password to minimize the risk of exploitation. Restrict access to the system to only necessary personnel and limit network access to reduce the attack surface.

Using Hardcoded Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08540
CVE-2023-6448

Produtos afetados

Unitronics Visilogic
Unitronics Vision Series Hmis
Unitronics Vision Series Plcs