Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions disclosed a high-severity vulnerability affecting multiple GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, GENESIS, and MC Works 64 products. The flaw, tracked as CWE-312 for cleartext storage of sensitive information, occurs when local caching with SQLite is enabled and SQL authentication is used, causing SQL Server credentials to be stored in plaintext in local cache files. CISA said the issue could allow information disclosure and could also enable tampering or denial-of-service conditions; the advisory assigned the vulnerability a CVSS v3.1 score of 8.8.
Mitsubishi Electric released fixes in version 10.98 or later for several affected product lines and version 11.03 or later for GENESIS, while no fix is planned for MC Works 64. CISA and the vendor urged operators to disable local cache where possible, delete cached database files, use Windows authentication instead of SQL authentication, and reduce exposure by restricting administrative and remote access, segmenting affected systems on internal networks, and limiting physical and network access to industrial control environments.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
CISA published advisory ICSA-26-097-01 describing the cleartext storage issue as a CWE-312 vulnerability with a CVSS v3.1 score of 8.8. The advisory recommended mitigations including disabling local cache, deleting cached database files, using Windows authentication, and restricting remote and network exposure.
Mitsubishi Electric released fixes in version 10.98 or later for several affected products and version 11.03 or later for GENESIS. The advisory states that no fix is planned for MC Works 64.
Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions disclosed a high-severity vulnerability affecting multiple GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, GENESIS, and MC Works 64 products. The flaw occurs when local caching with SQLite is enabled and SQL authentication is used, causing SQL Server credentials to be stored in plaintext in local cache files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.