PatchSiren cyber security CVE debrief
CVE-2024-1480 Unitronics CVE debrief
A critical vulnerability in Unitronics Vision Legacy series PLCs allows remote, unauthenticated attackers to retrieve the 'Information Mode' password in plaintext. This exposes affected industrial control systems to unauthorized access and potential operational disruption. The vulnerability carries a HIGH severity CVSS 3.1 score of 7.5, reflecting its network attack vector, low complexity, and high confidentiality impact. CISA published this advisory on April 18, 2024, with an update on April 30, 2024 adding vendor mitigations. The affected products span five Vision Legacy PLC models: Vision 120, 230, 280, 290, and 530, all versions. No known exploitation in ransomware campaigns has been reported.
- Vendor
- Unitronics
- Product
- Vision 230
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-04-18
- Original CVE updated
- 2024-04-30
- Advisory published
- 2024-04-18
- Advisory updated
- 2024-04-30
Who should care
Industrial control system operators, OT security teams, manufacturing security personnel, critical infrastructure defenders, and organizations using Unitronics Vision Legacy PLCs in production environments should prioritize assessment and mitigation of this vulnerability.
Technical summary
The Unitronics Vision Legacy series PLCs expose the 'Information Mode' password in plaintext to remote, unauthenticated attackers. This password disclosure vulnerability enables unauthorized individuals to gain administrative access to PLC configuration and operational parameters. The attack requires network access to the PLC, typically via TCP/20256 (default programmer port). The vulnerability affects all versions of five PLC models: Vision 120, 230, 280, 290, and 530. No patch is available; mitigation relies on configuration changes and network access controls.
Defensive priority
HIGH
Recommended defensive actions
- Change the default 'Info Mode' password (1111) via system integer SI 253 on affected PLCs
- Restrict Ethernet access to PLCs with Ethernet cards by implementing PLC multi-factor access using SB 314
- Apply multi-factor VPN protection for remote access to PLC services
- Restrict access to TCP/20256 by changing the default programmer port or applying multi-factor VPN protection
- Follow Unitronics published recommendations or contact Unitronics technical support for additional guidance
- Apply network segmentation to isolate affected PLCs from untrusted networks
- Monitor for unauthorized access attempts on TCP/20256 and PLC management interfaces
Evidence notes
Source: CISA CSAF advisory ICSA-24-109-01. CVSS 3.1 vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. Affected products confirmed via CSAF product tree: Vision 230, 280, 290, 530, 120 (all versions). Vendor mitigations added in Update A (April 30, 2024).
Sources and references
Verified primary and authoritative sources
-
CVE-2024-1480 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-1480
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-1480 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-1480
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-109-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-109-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.