WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships ICS/OT Cybersecurity – Unitronics Issues Update to Recently Targeted PLCs
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

ICS/OT Cybersecurity – Unitronics Issues Update to Recently Targeted PLCs

Author: Jennifer Walker

Created: Thursday, December 14, 2023 - 20:35

Categories: OT-ICS Security

Members using impacted Unitronics Vision or Samba PLCs are highly encouraged to apply VisiLogic version 9.9.00 to existing devices in your environment. Version 9.9.00 has incorporated security enhancements to mitigate the default configuration issues and vulnerability (CVE-2023-6448) that have enabled recent attacks/defacements against the internet connected PLC’s from the CyberAv3ngers identified in the referenced alert, (TLP:CLEAR) CISA Releases Alert on Exploitation of Unitronics PLCs Used in Water and Wastewater Systems.

According to Unitronics, among other enhancements, VisiLogic 9.9.00 provides new security features to protect networked controllers from cybersecurity threats.

  • From this version of VisiLogic on, the Equipment Level cybersecurity measures described in the Unitronics’ document hosted on our website, ‘Cyber Protection—Defending your Unitronics Samba™ and Vision™ series controllers’ are mandatory.
  • This version of VisiLogic requires you to change default passwords and implement complex passwords, and comprises new features to protect Vision and Samba controllers.

Relevant Resource Links:

  • https://www.unitronicsplc.com/cyber_security_vision-samba/

Additional WaterISAC Posts:

  • (TLP:CLEAR) Water Utility Control System Cyber Incident Advisory: ICS/SCADA Incident at Municipal Water Authority of Aliquippa (Updated November 30, 2023)
  • (TLP:CLEAR) CISA Releases Alert on Exploitation of Unitronics PLCs Used in Water and Wastewater Systems
  • WaterISAC Advisory: (TLP:CLEAR) CISA and Partners Confirm Additional Activity into Exploitation of Unitronics PLCs Across the U.S. Water and Wastewater Sector
  • (U//FOUO) Update to IRGC Attributed Activity Targeting Unitronics PLCs (Updated December 12, 2023)

 

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 7, 2026)

May 7, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness
Members Only

(TLP:GREEN) Individual Charged in Water System Tampering Incident

May 7, 2026 in Cybersecurity, OT-ICS Security, Security Preparedness

(TLP:CLEAR) AI-Assisted Water Utility Intrusion Underscores Growing OT Exposure Risk

May 7, 2026 in Contamination, OT-ICS Security, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar