Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Very High

CVE-2023-6448

Disclosure Date: December 05, 2023 (last updated June 27, 2024)
Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.
Attacker Value
Unknown

CVE-2024-38435

Disclosure Date: July 21, 2024 (last updated August 31, 2024)
Unitronics Vision PLC – CWE-703: Improper Check or Handling of Exceptional Conditions may allow denial of service
Attacker Value
Unknown

CVE-2024-38434

Disclosure Date: July 21, 2024 (last updated July 21, 2024)
Unitronics Vision PLC – CWE-676: Use of Potentially Dangerous Function may allow security feature bypass
0
Attacker Value
Unknown

CVE-2024-1480

Disclosure Date: April 19, 2024 (last updated April 20, 2024)
Unitronics Vision Standard line of controllers allow the Information Mode password to be retrieved without authentication.
0
Attacker Value
Unknown

CVE-2024-27774

Disclosure Date: March 18, 2024 (last updated April 01, 2024)
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-259: Use of Hard-coded Password may allow disclosing Sensitive Information Embedded inside Device's Firmware
0
Attacker Value
Unknown

CVE-2024-27773

Disclosure Date: March 18, 2024 (last updated April 01, 2024)
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-348: Use of Less Trusted Source may allow RCE
0
Attacker Value
Unknown

CVE-2024-27772

Disclosure Date: March 18, 2024 (last updated April 01, 2024)
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-78: 'OS Command Injection' may allow RCE
0
Attacker Value
Unknown

CVE-2024-27771

Disclosure Date: March 18, 2024 (last updated April 01, 2024)
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE
0
Attacker Value
Unknown

CVE-2024-27770

Disclosure Date: March 18, 2024 (last updated April 01, 2024)
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-23: Relative Path Traversal
0
Attacker Value
Unknown

CVE-2024-27769

Disclosure Date: March 18, 2024 (last updated April 01, 2024)
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor may allow Taking Ownership Over Devices
0