Coverage › CVE-2023-6448
CVE-2023-6448 Unmapped
Unitronics Vision PLC and HMI Insecure Default Password Vulnerability
- Vendor / product
- Unitronics — Vision PLC and HMI
- Description (CISA)
- Unitronics Vision Series PLCs and HMIs ship with an insecure default password, which if left unchanged, can allow attackers to execute remote commands.
- Added to KEV
- 2023-12-11
- Due date
- 2023-12-18
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Known ransomware use
- Unknown
- CWE
- CWE-1188
- CISA notes
- Note that while it is possible to change the default password, implementors are encouraged to remove affected controllers from public networks and update the affected firmware: https://downloads.unitronicsplc.com/Sites/plc/Technical_Library/Unitronics-Cybersecurity-Advisory-2023-001-CVE-2023-6448.pdf
https://nvd.nist.gov/vuln/detail/CVE-2023-6448 - Elsewhere
- cve.org · NVD · CISA KEV · JSON
ATT&CK techniques
No public source states how this vulnerability is exploited in ATT&CK terms.
The only authoritative CVE → ATT&CK mapping in the open — CTID's Mappings Explorer, pinned to a KEV snapshot of 2025-07-28 and ATT&CK 16.1 — does not include CVE-2023-6448. CISA's catalogue carries no technique field. kevmap does not infer techniques from the CWE (CWE-1188) — here is why — and does not guess.
This page will change state automatically if a mapping is published. What is shown above is everything CISA publishes about the entry.