Vulnary
← back to the feed
Critical· 9.3

CVE-2025-14815

A local attacker can obtain SQL Server credentials stored in plaintext within a local SQLite file when the local caching feature using SQLite is enabled and SQL authentication is used for SQL Server access. This affects multiple Mitsubishi Electric products (GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, GENESIS, MC Works64, and their Iconics Digital Solutions variants) at versions 10.97.3 and prior, or 11.02 and prior for GENESIS. With these credentials, an attacker could access, modify, or destroy data on the SQL Server and potentially cause a denial-of-service condition.

publishedApr 8, 2026
last modifiedJul 24, 2026
sourcesNVD
severity · cvss
9.3
critical · how bad it is
exploitation · epss
<1%
1th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 7, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, ICONICS Suite versions 10.97.3 and prior, MobileHMI versions 10.97.3 and prior, Hyper Historian versions 10.97.3 and prior, AnalytiX versions 10.97.3 and prior, GENESIS versions 11.02 and prior, MC Works64 all versions, and the corresponding Iconics Digital Solutions editions of those products.

02

Real-world impact

An attacker with local access could read the SQL Server credentials, then use them to log in to the database server, leading to data disclosure, tampering, destruction, or a denial-of-service.

03

Why this severity

The vulnerability is rated critical (CVSS 9.3) because it allows a low‑privilege local attacker to gain high impact on confidentiality, integrity, and availability of the SQL Server without needing user interaction.

04

What to do about it

no official fix yet
interim mitigations
  • Disable the local caching feature that uses SQLite if it is not required.
  • Switch from SQL Server authentication to Windows (trusted) authentication so credentials are not stored in plaintext.
  • Restrict local access to the affected systems to trusted administrators only.

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

No fix documented in sources; mitigations derived from the conditions described in the NVD description.

05

Timeline

  1. Apr 8, 2026 · Apr 8, 2026
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 24, 2026 · 11d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorLocal
Attack complexityLow
Attack requirementsNone
Privileges requiredLow
User interactionNone needed
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →