Executive brief
A vulnerability in several Mitsubishi Electric industrial automation software products allows a local user to view database credentials in plain text through the application's user interface. These products are used to monitor and control industrial processes, and an attacker with local access could use these stolen credentials to access the underlying SQL Server. This could lead to unauthorized data theft, tampering with industrial records, or causing a service outage.
Technical details
A Cleartext Storage of Sensitive Information in GUI vulnerability (CWE-317) exists in the Hyper Historian Splitter feature of multiple Mitsubishi Electric products. When SQL authentication is configured for the SQL Server connection, the credentials are displayed or stored in plain text within the graphical user interface. A local attacker with low privileges can exploit this to obtain administrative database credentials. With these credentials, the attacker can gain full access to the SQL Server to disclose, modify, or delete data, or disrupt system operations. Mitsubishi Electric has released updates for most products (v10.98 or v11.03), though no fix is planned for MC Works64.
Affected products
- Mitsubishi Electric GENESIS64 10.97.3 and prior
- Mitsubishi Electric ICONICS Suite 10.97.3 and prior
- Mitsubishi Electric MobileHMI 10.97.3 and prior
- Mitsubishi Electric Hyper Historian 10.97.3 and prior
- Mitsubishi Electric AnalytiX 10.97.3 and prior
- Mitsubishi Electric GENESIS 11.02 and prior
- Mitsubishi Electric MC Works64 all versions
Timeline
- 2026-04-07: advisory: Initial advisory released by Mitsubishi Electric and CISA (ICSA-26-097-01)
- 2026-04-08: disclosed: CVE published to NVD