PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-1480 Unitronics CVE debrief

A critical vulnerability in Unitronics Vision Legacy series PLCs allows remote, unauthenticated attackers to retrieve the 'Information Mode' password in plaintext. This exposes affected industrial control systems to unauthorized access and potential operational disruption. The vulnerability carries a HIGH severity CVSS 3.1 score of 7.5, reflecting its network attack vector, low complexity, and high confidentiality impact. CISA published this advisory on April 18, 2024, with an update on April 30, 2024 adding vendor mitigations. The affected products span five Vision Legacy PLC models: Vision 120, 230, 280, 290, and 530, all versions. No known exploitation in ransomware campaigns has been reported.

Vendor
Unitronics
Product
Vision 230
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-04-18
Original CVE updated
2024-04-30
Advisory published
2024-04-18
Advisory updated
2024-04-30

Who should care

Industrial control system operators, OT security teams, manufacturing security personnel, critical infrastructure defenders, and organizations using Unitronics Vision Legacy PLCs in production environments should prioritize assessment and mitigation of this vulnerability.

Technical summary

The Unitronics Vision Legacy series PLCs expose the 'Information Mode' password in plaintext to remote, unauthenticated attackers. This password disclosure vulnerability enables unauthorized individuals to gain administrative access to PLC configuration and operational parameters. The attack requires network access to the PLC, typically via TCP/20256 (default programmer port). The vulnerability affects all versions of five PLC models: Vision 120, 230, 280, 290, and 530. No patch is available; mitigation relies on configuration changes and network access controls.

Defensive priority

HIGH

Recommended defensive actions

  • Change the default 'Info Mode' password (1111) via system integer SI 253 on affected PLCs
  • Restrict Ethernet access to PLCs with Ethernet cards by implementing PLC multi-factor access using SB 314
  • Apply multi-factor VPN protection for remote access to PLC services
  • Restrict access to TCP/20256 by changing the default programmer port or applying multi-factor VPN protection
  • Follow Unitronics published recommendations or contact Unitronics technical support for additional guidance
  • Apply network segmentation to isolate affected PLCs from untrusted networks
  • Monitor for unauthorized access attempts on TCP/20256 and PLC management interfaces

Evidence notes

Source: CISA CSAF advisory ICSA-24-109-01. CVSS 3.1 vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. Affected products confirmed via CSAF product tree: Vision 230, 280, 290, 530, 120 (all versions). Vendor mitigations added in Update A (April 30, 2024).

Sources and references

Verified primary and authoritative sources

  • CVE-2024-1480 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-1480

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-1480 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-1480

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-109-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-109-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.