Junglewise Threat Intelligence

CVE-2025-14815: Mitsubishi Electric GENESIS64 and ICONICS Suite cleartext storage of credentials

CVE-2025-14815 · Severity: info · CVSS 9.3 · Published 2026-04-08

Vendors: Mitsubishi Electric.

Executive brief

Multiple Mitsubishi Electric industrial automation and monitoring products are affected by a security flaw where database credentials are stored in plain text on the local system. These products are used to manage and visualize industrial control systems; if an attacker gains local access to a machine running this software, they could steal the credentials to access the underlying SQL Server. This could allow them to view sensitive operational data, modify system configurations, or disrupt industrial processes.

Technical details

A Cleartext Storage of Sensitive Information vulnerability (CWE-312) exists in several Mitsubishi Electric products when the local caching feature using SQLite is enabled and SQL authentication is used for the SQL Server. A local attacker with low privileges can access the local SQLite cache files (typically located in ProgramData) to retrieve plaintext SQL Server credentials. Successful exploitation allows the attacker to authenticate to the SQL Server with the stolen credentials to disclose, modify, or delete data, or cause a denial-of-service. Patches are available for most products (v10.98 or v11.03), though MC Works64 has no planned fix and requires manual mitigation by disabling the local cache and deleting existing cache files.

Affected products

  • Mitsubishi Electric GENESIS64 10.97.3 and prior
  • Mitsubishi Electric ICONICS Suite 10.97.3 and prior
  • Mitsubishi Electric MobileHMI 10.97.3 and prior
  • Mitsubishi Electric Hyper Historian 10.97.3 and prior
  • Mitsubishi Electric AnalytiX 10.97.3 and prior
  • Mitsubishi Electric GENESIS 11.02 and prior
  • Mitsubishi Electric MC Works64 all versions

Timeline

  • 2026-04-07: advisory: CISA and JVN published advisories.
  • 2026-04-08: disclosed: CVE-2025-14815 published.

References

Related threats