Executive Summary
In May 2025, Mitsubishi Electric disclosed a vulnerability (CVE-2025-0921) in their GENESIS64, MC Works64, and GENESIS products. This flaw allows local attackers to perform unauthorized writes to arbitrary files by exploiting symbolic links, potentially leading to denial-of-service conditions. The vulnerability affects all versions of GENESIS64 and MC Works64, as well as GENESIS version 11.00. Mitsubishi Electric has released patches and mitigation strategies to address this issue. (mitsubishielectric.com)
This incident underscores the critical importance of securing industrial control systems against local privilege escalation attacks, which can disrupt essential operations. Organizations are urged to apply the provided patches promptly and review their security protocols to prevent similar vulnerabilities.
Why This Matters Now
The rise in local privilege escalation attacks targeting industrial control systems highlights the need for immediate action to secure critical infrastructure. Delaying patch implementation increases the risk of operational disruptions and potential data breaches.
Attack Path Analysis
An attacker exploited the cleartext storage of SQL Server credentials in Mitsubishi Electric's GENESIS64 and ICONICS Suite products to gain unauthorized access. With these credentials, the attacker escalated privileges within the SQL Server environment. They then moved laterally across the network to access other critical systems. Establishing command and control, the attacker exfiltrated sensitive data. Finally, they caused a denial-of-service condition, disrupting operations.
Kill Chain Progression
Initial Compromise
Description
The attacker exploited the cleartext storage of SQL Server credentials in the affected products to gain unauthorized access.
Related CVEs
CVE-2025-14815
CVSS 9.3Cleartext storage of SQL Server credentials in local SQLite files when local caching is enabled and SQL authentication is used, potentially leading to information disclosure, data tampering, or denial-of-service.
Affected Products:
Mitsubishi Electric GENESIS64 – <=10.97.3
Mitsubishi Electric ICONICS Suite – <=10.97.3
Mitsubishi Electric MobileHMI – <=10.97.3
Mitsubishi Electric Hyper Historian – <=10.97.3
Mitsubishi Electric AnalytiX – <=10.97.3
Mitsubishi Electric MC Works 64 – all versions
Mitsubishi Electric GENESIS – <=11.02
Exploit Status:
no public exploitCVE-2025-14816
CVSS 9.3SQL Server credentials displayed in plain text within the GUI of the Hyper Historian Splitter feature when SQL authentication is used, potentially leading to information disclosure, data tampering, or denial-of-service.
Affected Products:
Mitsubishi Electric GENESIS64 – <=10.97.3
Mitsubishi Electric ICONICS Suite – <=10.97.3
Mitsubishi Electric MobileHMI – <=10.97.3
Mitsubishi Electric Hyper Historian – <=10.97.3
Mitsubishi Electric AnalytiX – <=10.97.3
Mitsubishi Electric MC Works 64 – all versions
Mitsubishi Electric GENESIS – <=11.02
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Credentials from Password Stores: Credentials from Web Browsers
OS Credential Dumping: LSASS Memory
Valid Accounts
Network Denial of Service
Data Destruction
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Secure storage of cardholder data
Control ID: 3.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Credential Management
Control ID: Pillar 2: Identity
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Industrial Automation
Critical Manufacturing sectors face high risk from ICS vulnerabilities exposing SQL credentials in Mitsubishi Electric SCADA systems, enabling data tampering and DoS attacks.
Utilities
Power and water utilities using affected Mitsubishi GENESIS64/ICONICS products vulnerable to credential theft allowing unauthorized control system access and service disruption.
Oil/Energy/Solar/Greentech
Energy infrastructure relies heavily on affected ICS platforms where plaintext credential storage creates pathways for operational technology compromise and production interference.
Automotive
Manufacturing plants using Mitsubishi Electric automation systems face production line disruption risks through exposed database credentials enabling lateral movement and system manipulation.
Sources
- Mitsubishi Electric GENESIS64 and ICONICS Suite productshttps://www.cisa.gov/news-events/ics-advisories/icsa-26-097-01Verified
- Malicious Code Execution Vulnerability in the Software Keyboard Function of GENESIS64, ICONICS Suite, Mobile HMI, and MC Works64https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-018_en.pdfVerified
- GENESIS64 version 10.98 Now Availablehttps://iconics.com/news/press-releases/2026/genesis64-version10-98Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's lateral movement and data exfiltration, thereby reducing the overall impact.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF may not prevent initial credential exposure, it could limit the attacker's ability to leverage these credentials across the network.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could likely limit the attacker's ability to escalate privileges by enforcing strict access controls.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could likely reduce the attacker's ability to move laterally by enforcing strict segmentation policies.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could likely detect and limit unauthorized command and control communications.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could likely limit the attacker's ability to exfiltrate data by controlling outbound traffic.
While Aviatrix Zero Trust CNSF may not prevent all denial-of-service attacks, it could likely reduce their impact by limiting the attacker's reach within the network.
Impact at a Glance
Affected Business Functions
- Industrial Control Systems Operations
- Data Management
- System Monitoring
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of SQL Server credentials leading to unauthorized access to sensitive operational data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and prevent lateral movement.
- • Enable East-West Traffic Security to monitor and control internal network communications.
- • Deploy Inline IPS (Suricata) to detect and prevent exploitation attempts.
- • Utilize Multicloud Visibility & Control to gain comprehensive insights into network activities.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.



