Unitronics manufactures industrial automation controllers and their associated development platforms, including products such as UniLogic and Visilogic that are deployed in critical operational technology environments. Vulnerabilities affecting this vendor skew strongly toward critical severity and recur through weakness classes including path traversal, buffer-boundary violations, hard-coded credentials, and embedded malicious code—flaws that reflect both the legacy security posture of embedded firmware and the memory constraints typical of industrial control devices. A moderate share of the vendor's disclosures has attracted confirmed in-the-wild exploitation; defenders should prioritize inventory and assessment of affected controller models and development tooling, particularly those exposed to untrusted networks. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Unitronics over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-6448CRITICAL Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take | Dec 5, 2023 | 9.8 | 71 | YES | NO |
CVE-2024-27767CRITICAL
CWE-287: Improper Authentication may allow Authentication Bypass
| Mar 18, 2024 | 9.8 | 30 | NO | NO |
CVE-2023-2003CRITICAL Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded malicious code in t | Jul 13, 2023 | 9.8 | 30 | NO | NO |
CVE-2016-4519CRITICAL Stack-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.30 allows remote attackers to execute arbitrary code via a crafted filename field in a ZIP archive in a vlp | Jun 25, 2016 | 9.8 | 30 | NO | NO |
CVE-2024-27768CRITICAL
Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-22: 'Path Traversal' may allow RCE
| Mar 18, 2024 | 9.8 | 27 | NO | NO |
CVE-2015-7905HIGH Unitronics VisiLogic OPLC IDE before 9.8.02 allows remote attackers to execute unspecified code via unknown vectors. | Nov 13, 2015 | 7.5 | 26 | NO | NO |
CVE-2024-27772HIGH
Unitronics Unistream Unilogic – Versions prior to 1.35.227 -
CWE-78: 'OS Command Injection' may allow RCE
| Mar 18, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-27771HIGH
Unitronics Unistream Unilogic – Versions prior to 1.35.227 -
CWE-22: 'Path Traversal' may allow RCE
| Mar 18, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-27770HIGH
Unitronics Unistream Unilogic – Versions prior to 1.35.227 -
CWE-23: Relative Path Traversal
| Mar 18, 2024 | 8.8 | 25 | NO | NO |
CVE-2015-7939CRITICAL Heap-based buffer overflow in Unitronics VisiLogic OPLC IDE before 9.8.09 allows remote attackers to execute arbitrary code via a long vlp filename. | Jan 9, 2016 | 9.6 | 25 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Unitronics.
Media articles that mention a CVE ID that affects a product developed by Unitronics — matched by CVE ID, not by vendor name.