CVE-2023-6448
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.
Affected (17)
Products: Unitronics: Vision1210 Firmware, Vision1040 Firmware, Vision700 Firmware, Vision570 Firmware, Vision560 Firmware, Vision430 Firmware, Vision350 Firmware, Vision130 Firmware, Vision230 Firmware, Vision280 Firmware, Vision290 Firmware, Vision530 Firmware, Vision120 Firmware, Visilogic, Samba 3.5 Firmware, Samba 4.3 Firmware, Samba 7 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.38 |
| Running on/with | Platform Versions |
|---|---|
Unitronics Vision1210 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.38 |
| Running on/with | Platform Versions |
|---|---|
Unitronics Vision1040 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.38 |
| Running on/with | Platform Versions |
|---|---|
Unitronics Vision700 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.38 |
| Running on/with | Platform Versions |
|---|---|
Unitronics Vision570 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.38 |
| Running on/with | Platform Versions |
|---|---|
Unitronics Vision560 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.38 |
| Running on/with | Platform Versions |
|---|---|
Unitronics Vision430 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.38 |
| Running on/with | Platform Versions |
|---|---|
Unitronics Vision350 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.38 |
| Running on/with | Platform Versions |
|---|---|
Unitronics Vision130 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.38 |
| Running on/with | Platform Versions |
|---|---|
Unitronics Vision230 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.38 |
| Running on/with | Platform Versions |
|---|---|
Unitronics Vision280 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.38 |
| Running on/with | Platform Versions |
|---|---|
Unitronics Vision290 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.38 |
| Running on/with | Platform Versions |
|---|---|
Unitronics Vision530 | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.38 |
| Running on/with | Platform Versions |
|---|---|
Unitronics Vision120 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 9.9.00 |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.38 |
| Running on/with | Platform Versions |
|---|---|
Unitronics Samba 3.5 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.38 |
| Running on/with | Platform Versions |
|---|---|
Unitronics Samba 4.3 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.38 |
| Running on/with | Platform Versions |
|---|---|
Unitronics Samba 7 | All versions |
Related CWEs
CWE-1188
Initialization of a Resource with an Insecure Default
The product initializes or sets a resource with a default that is intended to be changed by the administrator, but the default is not secure.
CWE-798
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
References (9)
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Vendor Advisory
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Release Notes
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Third Party AdvisoryUS Government Resource
Source: 9119a7d8-5eab-497f-8521-727c672e3725
Product
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Product
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource
Timeline
No history available yet.