WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships ICS/OT/SCADA Vulnerability Awareness – Unitronics Vision Series PLCs | Storing Passwords in a Recoverable Format
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

ICS/OT/SCADA Vulnerability Awareness – Unitronics Vision Series PLCs | Storing Passwords in a Recoverable Format

Author: Jennifer Walker

Created: Thursday, April 18, 2024 - 18:07

Categories: OT-ICS Security

Given recent attention and attacks against Unitronics Vision Series PLCs and their use in the water and wastewater systems sector, WaterISAC is amplifying this recent vulnerability advisory. Members using Unitronics Vision Series PLCs are highly encouraged to review the following ICS Advisory and address accordingly.

Unitronics Vision Series PLCs | ICSA-24-109-01

Vulnerability: Storing Passwords in a Recoverable Format

  • Unitronics Vision Standard PLCs allow a remote, unauthenticated individual to retrieve the ‘Information Mode’ password in plaintext.
  • Successful exploitation of this vulnerability could allow an attacker to log in to the Remote HMI feature, where the PLC may be factory reset, stopped, and restarted.
  • This vulnerability is remotely exploitable and has a low attack complexity.
  • CVE-2024-1480 has been assigned to this vulnerability.

Mitigations: This vulnerability was discovered by Dragos who recommends users to restrict access to the PLC on TCP/20256 by either changing the default programmer port, or apply a multi-factor VPN to protect the service from remote access.

For additional mitigations, visit the CISA ICS Advisory, Unitronics Vision Series PLCs | ICSA-24-109-01

Related Resources

(TLP:CLEAR) CISA ICS Advisories, Additional Alerts, Updates, and Bulletins – April 23, 2026

Apr 23, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated April 23, 2026)

Apr 17, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

(TLP:CLEAR) Securin Cyber Threat Intelligence Report: Water & Wastewater Systems

Apr 16, 2026 in Cybersecurity, OT-ICS Security, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar