TROYANOSYVIRUS
Voltar para CVEs

CVE-2023-6448

CRITICALCISA KEV
9.8

Descricao

Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.

Detalhes CVE

Pontuacao CVSS v3.19.8
SeveridadeCRITICAL
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosNONE
Interacao do usuarioNONE
Publicado12/5/2023
Ultima modificacao2/26/2026
Fontekev
Avistamentos honeypot0

CISA KEV

FornecedorUnitronics
ProdutoVision PLC and HMI
Nome da vulnerabilidadeUnitronics Vision PLC and HMI Insecure Default Password Vulnerability
Data inclusao KEV2023-12-11
Prazo de remediacao2023-12-18
Uso em ransomwareUnknown

Produtos afetados

unitronics:samba_3.5unitronics:samba_3.5_firmwareunitronics:samba_4.3unitronics:samba_4.3_firmwareunitronics:samba_7unitronics:samba_7_firmwareunitronics:visilogicunitronics:vision1040unitronics:vision1040_firmwareunitronics:vision120unitronics:vision120_firmwareunitronics:vision1210unitronics:vision1210_firmwareunitronics:vision130unitronics:vision130_firmwareunitronics:vision230unitronics:vision230_firmwareunitronics:vision280unitronics:vision280_firmwareunitronics:vision290unitronics:vision290_firmwareunitronics:vision350unitronics:vision350_firmwareunitronics:vision430unitronics:vision430_firmwareunitronics:vision530unitronics:vision530_firmwareunitronics:vision560unitronics:vision560_firmwareunitronics:vision570unitronics:vision570_firmwareunitronics:vision700unitronics:vision700_firmware

Fraquezas (CWE)

CWE-1188CWE-798

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.