December 11, 2023 · Applied Cybernetics Group
CVE-2023-6448 — Unitronics Vision PLC and HMI
Unitronics Vision PLC and HMI Insecure Default Password Vulnerability
- Added to KEV
2023-12-11- Federal due date
2023-12-18- Vendor
- Unitronics
- Product
- Vision PLC and HMI
- EPSS
- 94.3th percentile (score 0.133, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2023-6448
CISA short description
Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.