LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-6448: Unitronics Vision PLC and HMI Insecure Default Password Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 11, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Dec 18, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-6448 to its Known Exploited Vulnerabilities catalog on Dec 11, 2023, with a federal patch deadline of Dec 18, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands.

CVE-2023-6448 is an insecure default password vulnerability affecting Unitronics Vision Series PLCs and HMIs. These industrial control devices ship with a default password that, if left unchanged, can allow remote attackers to execute commands on the system. For operators of manufacturing, utilities, or other OT environments that rely on these controllers, the issue matters because unauthenticated or weakly authenticated remote access to PLCs and HMIs can lead to process disruption, unauthorized configuration changes, or further network compromise.

Public detail is limited to the CISA summary and the CWE classification; teams should treat any device still using the factory credential as immediately at risk and confirm exact product scope and remediation steps against the vendor advisory.

How it works

The vulnerability is classified as CWE-1188 (Insecure Default Initialization of Resource). Unitronics Vision Series PLCs and HMIs are delivered with a known default password. When that password is not changed after installation, an attacker who can reach the device over the network can authenticate with the factory credential and then execute remote commands.

In practice this means the authentication boundary that should protect the controller is effectively absent. An adversary does not need to crack a password or exploit a complex memory-corruption bug; they simply use the documented default. Once authenticated, the attacker can issue commands that the PLC or HMI is designed to accept from a legitimate operator. Specific command sets, protocols, or ports involved are not detailed in the available summary and must be confirmed against the vendor advisory.

Am I affected? How to find it in your systems

Unitronics Vision PLCs and HMIs are typically found in industrial automation, building management, water/wastewater, and discrete manufacturing environments. They may be connected to engineering workstations, SCADA servers, or directly to plant networks.

Because version ranges and exact model lists are not supplied in the provided facts, treat every Vision Series PLC or HMI as potentially affected until the vendor advisory is consulted.

How to remediate

The primary remediation is to follow the vendor’s instructions for changing the default password and applying any accompanying firmware or configuration updates. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Hardening steps that apply to this class of weakness include enforcing unique credentials at commissioning, disabling unused remote-access services, and ensuring that password-change procedures are part of the standard deployment checklist for all new controllers.

If you can't patch immediately

If an immediate password change or firmware update cannot be performed, reduce exposure with compensating controls until the permanent fix is applied.

These measures lower the probability of opportunistic exploitation but do not eliminate the underlying risk; schedule the permanent password change as soon as operationally possible.

If your data may have been exposed

Actively exploited vulnerabilities of this type have been used to gain initial access to industrial environments and can lead to broader breaches. Although ransomware use specifically tied to CVE-2023-6448 is not documented in the available facts, any successful remote command execution on a PLC or HMI should be treated as a potential incident. Review network and device logs for signs of unauthorized access, isolate affected systems, and follow your incident-response plan. You can also run a free exposure scan of your email addresses to check whether they appear in known breach data sets, which may indicate secondary credential compromise that could be used against engineering workstations or remote-access portals.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedUnitronics · Vision PLC and HMI
WeaknessCWE-1188
Added to CISA KEVDec 11, 2023
Federal patch deadlineDec 18, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities