Mitsubishi Electric and Mitsubishi Electric Iconics Digital Solutions disclosed multiple vulnerabilities affecting ICONICS Suite, GENESIS64, GENESIS32, MC Works64, and related products used in industrial and manufacturing environments. CISA said the flaws include deserialization-based remote code execution, path traversal, inclusion of functionality from an untrusted control sphere, and an out-of-bounds read that could lead to information disclosure or denial of service. The most severe issue carries a CVSS v3.1 score of 9.8, and affected versions include GENESIS64 and ICONICS Suite 10.97 through 10.97.1, MC Works64 up to 4.04E, and GENESIS32 up to 9.7.
A separate updated advisory also detailed an information tampering flaw caused by execution with unnecessary privileges across additional ICONICS-related products, including MobileHMI, Hyper Historian, AnalytiX, IoTWorX, GENESIS, and BizViz. CISA said a low-privileged local attacker could create a symbolic link and abuse service file writes to overwrite arbitrary files, potentially destroying files and causing denial of service, a weakness tracked under CWE-250 and rated CVSS 6.5. Vendor fixes are available for several current product lines, including version 10.98 or later for GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, and AnalytiX, version 10.96 or later for IoTWorX, and version 11.01 or later for GENESIS, while no fixes are planned for some legacy products such as MC Works64, GENESIS32, and BizViz; operators are urged to isolate affected systems, restrict remote and physical access, and use firewalls or VPNs.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Vendor fixes were available for several current products, including version 10.98 or later for GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, and AnalytiX, version 10.96 or later for IoTWorX, and version 11.01 or later for GENESIS. No fixes were planned for some legacy products such as MC Works64, GENESIS32, and BizViz, with mitigations recommended instead.
CISA published Update F for an information tampering vulnerability caused by execution with unnecessary privileges in multiple ICONICS-related products, including GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, IoTWorX, MC Works64, GENESIS, GENESIS32, and BizViz. The flaw allows a low-privileged local attacker to abuse symbolic links and service file writes to perform unauthorized writes to arbitrary files, potentially causing denial of service.
Vendor fixes were made available for GENESIS64 and ICONICS Suite through ICONICS critical rollups, while Mitsubishi Electric said no security updates were planned for legacy MC Works64 and GENESIS32 products. Recommended mitigations included network isolation, firewalling, minimizing internet exposure, and avoiding untrusted links or attachments.
Mitsubishi Electric published an advisory covering multiple vulnerabilities in ICONICS Suite, GENESIS64, GENESIS32, and MC Works64, including path traversal, deserialization-based remote code execution, untrusted control sphere functionality, and an out-of-bounds read. The affected products were described as used in critical manufacturing environments worldwide, with the most severe issue rated CVSS 9.8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcecisa.gov
Open sourcemitsubishielectric.com
Open sourcemitsubishielectric.com
Open sourcemitsubishielectric.com
Open sourcemitsubishielectric.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.