
⚠️ **Vulnerability Alert:** CISA ICS Advisory: Mitsubishi Electric GENESIS64 and ICONICS Suite products (multiple ICS advisories/updates) 📅 **Timeline:** Disclosure: 2026-04-07, Patch: Multiple (see references) 🆔 **CVE-2025-14815** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: Not Available 🆔 **CVE-2025-14816** | 📊 CVSS: 8.8 (HIGH 🟠) | 📈 EPSS: Not Available 🆔 **CVE-2025-7376** | 📊 CVSS: 5.9 (MEDIUM 🟡) | 📈 EPSS: 1.456% 🆔 **CVE-2025-0921** | 📊 CVSS: 6.5 (MEDIUM 🟡) | 📈 EPSS: 20.714% 🆔 **CVE-2024-8299** | 📊 CVSS: 7.8 (HIGH 🟠) | 📈 EPSS: 6.927% 🆔 **CVE-2024-8300** | 📊 CVSS: 7.0 (HIGH 🟠) | 📈 EPSS: 10.572% 🆔 **CVE-2024-9852** | 📊 CVSS: 7.8 (HIGH 🟠) | 📈 EPSS: 6.927% 🆔 **CVE-2023-2650** | 📊 CVSS: 3.7 (LOW 🟢) | 📈 EPSS: 99.698% 🆔 **CVE-2023-4807** | 📊 CVSS: 5.9 (MEDIUM 🟡) | 📈 EPSS: 74.338% 🆔 **CVE-2024-1182** | 📊 CVSS: 7.0 (HIGH 🟠) | 📈 EPSS: 18.210% 🆔 **CVE-2024-1573** | 📊 CVSS: 5.9 (MEDIUM 🟡) | 📈 EPSS: 47.466% 🆔 **CVE-2024-1574** | 📊 CVSS: 6.7 (MEDIUM 🟡) | 📈 EPSS: 34.105% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** GENESIS64/ICONICS Suite/MobileHMI/Hyper Historian/AnalytiX <=10.97.3, MC Works64 — all versions, GENESIS <=11.03 (varies by advisory), IoTWorX 10.95, GENESIS32/BizViz — various versions 🔧 **Fixed Versions:** GENESIS64/ICONICS Suite/MobileHMI/Hyper Historian/AnalytiX: 10.98+, GENESIS: 11.01 / 11.03+, IoTWorX: 10.96+, No fix for MC Works64/GENESIS32/BizViz — vendor mitigations 🫨 **Attack Vectors:** - Local attacker / local access required - Cleartext storage of SQL credentials in local SQLite cache and plaintext display in GUI - Windows .LNK/symbolic-link exploitation enabling arbitrary writes - DLL search-path/DLL planting (uncontrolled search path) - OpenSSL parsing via BACnet Secure Connect (remote malformed cert/MAC) - Authentication bypass via AD + automatic logon conditions - Execution with unnecessary privileges / unsafe reflection 📝 **Summary:** Multiple local (and some remote) vulnerabilities across Mitsubishi/ICONICS ICS products expose plaintext SQL credentials, enable arbitrary file writes and DLL planting, and allow authentication bypass or unsafe code execution paths. Impacts include credential disclosure, tampering, denial-of-service, and, in some cases, elevated arbitrary code execution — patch immediately where available and apply mitigations for unpatchable products. 📈 **Impact Scope:** Affects multiple Mitsubishi Electric / ICONICS products used in critical manufacturing ICS: credential disclosure, information disclosure, arbitrary file tampering/deletion, DoS, and potential code execution with elevated privileges. 🛡️ **Recommended Actions:** - Apply vendor-supplied patches immediately; isolate ICS networks, restrict remote/admin logins and enforce least privilege. - Disable/delete local cache (C:\ProgramData\ICONICS\Cache\*.sdf and C:\ProgramData\ICONICS\11\Cache\*.sqlite3), prefer Windows auth for SQL Server, harden HHSplitter.exe, and follow vendor mitigations for unpatched products. 🪢 **Related Resources:** - https://www.youtube.com/watch?v=KsZ6tROaVOQ - https://en.wikipedia.org/wiki/2 🏷 **Tags:** #Cybersecurity #ICS #MitsubishiElectric
Post summary
The advisory announces multiple high‑score CVEs affecting Mitsubishi Electric and ICONICS products, detailing technical vectors and urging immediate patching while outlining workarounds for unpatched versions.
