{"api_version":"1","generated_at":"2026-07-23T14:53:03+00:00","cve":"CVE-2023-6448","urls":{"html":"https://cve.report/CVE-2023-6448","api":"https://cve.report/api/cve/CVE-2023-6448.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-6448","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-6448"},"summary":{"title":"Unitronics Vision PLC and HMI Insecure Default Password Vulnerability","description":"Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands.","state":"PUBLISHED","assigner":"","published_at":"2023-12-05 18:15:00","updated_at":"2023-12-05 20:13:00"},"problem_types":[],"metrics":[],"references":[{"url":"https://www.cisa.gov/news-events/alerts/2023/11/28/exploitation-unitronics-plcs-used-water-and-wastewater-systems","name":"https://www.cisa.gov/news-events/alerts/2023/11/28/exploitation-unitronics-plcs-used-water-and-wastewater-systems","refsource":"","tags":[],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-6448","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-6448","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2023","cve_id":"6448","cve":"CVE-2023-6448","vendorProject":"Unitronics","product":"Vision PLC and HMI","vulnerabilityName":"Unitronics Vision PLC and HMI Insecure Default Password Vulnerability","dateAdded":"2023-12-11","shortDescription":"Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands.","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","dueDate":"2023-12-18","knownRansomwareCampaignUse":"Unknown","notes":"Note that while it is possible to change the default password, implementors are encouraged to remove affected controllers from public networks and update the affected firmware: https://downloads.unitronicsplc.com/Sites/plc/Technical_Library/Unitronics-Cybersecurity-Advisory-2023-001-CVE-2023-6448.pdf;   https://nvd.nist.gov/vuln/detail/CVE-2023-6448","cwes":"CWE-1188","catalogVersion":"2026.07.22","updated_at":"2026-07-22 20:07:15"},"epss":{"cve_year":"2023","cve_id":"6448","cve":"CVE-2023-6448","epss":"0.020890000","percentile":"0.796340000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:32"},"legacy_qids":[{"cve":"CVE-2023-6448","qid":"379326","title":"Unitronics VisiLogic Insecure Default Password Vulnerability"}]},"source_records":{"cve_program":null,"nvd":{"publishedDate":"2023-12-05 18:15:00","lastModifiedDate":"2023-12-05 20:13:00","problem_types":[],"metrics":[],"configurations":{"CVE_data_version":"4.0","nodes":[]}},"legacy_mitre":{"record":null,"notes":[]}}}