
🚨 Unit 42 Details CVE-2025-0921 in ICONICS/GENESIS64: Privileged File Ops Can Brick SCADA Hosts Unit 42 analyzed CVE-2025-0921 (CVSS 6.5) in Mitsubishi Electric ICONICS Suite/GENESIS64 where a privileged Pager Agent workflow can be abused to perform unsafe file-system operations; when chained with the GenBroker32 installer flaw (CVE-2024-7587) that makes critical configs writable, a low-priv user can redirect logging to overwrite/corrupt binaries and trigger DoS, impacting OT availability/integrity. Apply the vendor advisory/workaround and update vulnerable ICONICS Suite versions (Windows 10.97.2 and earlier) to remove the exposure. 🎯 Target: Global/Industrial OT (SCADA) #️⃣ Category: #Vulnerability #BlueTeam #CyberIntel 🔗 URL: https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/
Post summary
Unit 42 discloses CVE‑2025‑0921 in ICONICS Suite/GENESIS64, detailing privileged file‑system operations that can trigger a DoS when chained with CVE‑2024‑7587, and urges users to apply the vendor advisory and update to newer versions.
