Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Unitronics

First CVE: Nov 13, 2015Active for: 11 yearsTotal CVEs: 15
52.8
VTI Score
TOP TARGET

Unitronics manufactures industrial automation controllers and their associated development platforms, including products such as UniLogic and Visilogic that are deployed in critical operational technology environments. Vulnerabilities affecting this vendor skew strongly toward critical severity and recur through weakness classes including path traversal, buffer-boundary violations, hard-coded credentials, and embedded malicious code—flaws that reflect both the legacy security posture of embedded firmware and the memory constraints typical of industrial control devices. A moderate share of the vendor's disclosures has attracted confirmed in-the-wild exploitation; defenders should prioritize inventory and assessment of affected controller models and development tooling, particularly those exposed to untrusted networks. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
0.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
8.7
Avg CVSS Score
Higher Avg CVSS Score than 83% of tracked vendors
6.7%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Unitronics over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 13, 2015
10 years ago
Most Recent CVE
Jul 21, 2024
733 days ago

Products(35 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-6448CRITICAL
Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take
Dec 5, 20239.871YESNO
CVE-2024-27767CRITICAL
CWE-287: Improper Authentication may allow Authentication Bypass
Mar 18, 20249.830NONO
CVE-2023-2003CRITICAL
Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded malicious code in t
Jul 13, 20239.830NONO
CVE-2016-4519CRITICAL
Stack-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.30 allows remote attackers to execute arbitrary code via a crafted filename field in a ZIP archive in a vlp
Jun 25, 20169.830NONO
CVE-2024-27768CRITICAL
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE
Mar 18, 20249.827NONO
CVE-2015-7905HIGH
Unitronics VisiLogic OPLC IDE before 9.8.02 allows remote attackers to execute unspecified code via unknown vectors.
Nov 13, 20157.526NONO
CVE-2024-27772HIGH
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-78: 'OS Command Injection' may allow RCE
Mar 18, 20248.825NONO
CVE-2024-27771HIGH
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE
Mar 18, 20248.825NONO
CVE-2024-27770HIGH
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-23: Relative Path Traversal
Mar 18, 20248.825NONO
CVE-2015-7939CRITICAL
Heap-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.09 allows remote attackers to execute arbitrary code via a long vlp filename.
Jan 9, 20169.625NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
13%
47%
40%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (86.7%)
Unknown2 (13.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (86.7%)
High0 (0.0%)
Unknown2 (13.3%)
User Interaction
None12 (80.0%)
Unknown2 (13.3%)
Required1 (6.7%)
Privileges Required
Low6 (40.0%)
High0 (0.0%)
None7 (46.7%)
Unknown2 (13.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
1 CVE
6.7% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Unitronics.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Unitronics — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Unitronics's Products

View all 3 CNAs →

Top CWEs