WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts ICS/OT/SCADA Vulnerability Awareness – Unitronics Vision Series PLCs | Storing Passwords in a Recoverable Format
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

ICS/OT/SCADA Vulnerability Awareness – Unitronics Vision Series PLCs | Storing Passwords in a Recoverable Format

Author: Jennifer Walker

Created: Thursday, April 18, 2024 - 18:07

Categories: OT-ICS Security

Given recent attention and attacks against Unitronics Vision Series PLCs and their use in the water and wastewater systems sector, WaterISAC is amplifying this recent vulnerability advisory. Members using Unitronics Vision Series PLCs are highly encouraged to review the following ICS Advisory and address accordingly.

Unitronics Vision Series PLCs | ICSA-24-109-01

Vulnerability: Storing Passwords in a Recoverable Format

  • Unitronics Vision Standard PLCs allow a remote, unauthenticated individual to retrieve the ‘Information Mode’ password in plaintext.
  • Successful exploitation of this vulnerability could allow an attacker to log in to the Remote HMI feature, where the PLC may be factory reset, stopped, and restarted.
  • This vulnerability is remotely exploitable and has a low attack complexity.
  • CVE-2024-1480 has been assigned to this vulnerability.

Mitigations: This vulnerability was discovered by Dragos who recommends users to restrict access to the PLC on TCP/20256 by either changing the default programmer port, or apply a multi-factor VPN to protect the service from remote access.

For additional mitigations, visit the CISA ICS Advisory, Unitronics Vision Series PLCs | ICSA-24-109-01

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated June 11, 2026)

Jun 11, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness
Members Only

(TLP:GREEN) CISA Invites Water and Wastewater Utilities to Participate in CI Fortify Technical Exchange Group

Jun 11, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

(TLP:CLEAR) CISA ICS Advisories, Additional Alerts, Updates, and Bulletins – June 11, 2026

Jun 11, 2026 in Cybersecurity, Federal & State Resources, OT-ICS Security

Become a Member
FAQs
About
Report Incident
Traffic Light Protocol (TLP)

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar