EXPOSURES › CVE-2023-6448
CVE-2023-6448
HIGH ⌖ ON CISA KEV · EXPLOITEDUnitronics Vision PLCs and HMIs ship with insecure default passwords enabling remote command execution.
This vulnerability allows attackers to execute remote commands on industrial control systems if default credentials are not changed, creating a critical supply-chain risk for DIB organizations relying on these devices. The default password is a known, avoidable flaw that bypasses authentication entirely, exposing OT environments to unauthorized access and potential ransomware entry points.
Shame score — Shipping industrial control hardware with known, exploitable default credentials is a severe negligence that directly compromises OT security and violates hardening standards.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands.