CVE-2025-14815
A local attacker can obtain SQL Server credentials stored in plaintext within a local SQLite file when the local caching feature using SQLite is enabled and SQL authentication is used for SQL Server access. This affects multiple Mitsubishi Electric products (GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, GENESIS, MC Works64, and their Iconics Digital Solutions variants) at versions 10.97.3 and prior, or 11.02 and prior for GENESIS. With these credentials, an attacker could access, modify, or destroy data on the SQL Server and potentially cause a denial-of-service condition.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, ICONICS Suite versions 10.97.3 and prior, MobileHMI versions 10.97.3 and prior, Hyper Historian versions 10.97.3 and prior, AnalytiX versions 10.97.3 and prior, GENESIS versions 11.02 and prior, MC Works64 all versions, and the corresponding Iconics Digital Solutions editions of those products.
Real-world impact
An attacker with local access could read the SQL Server credentials, then use them to log in to the database server, leading to data disclosure, tampering, destruction, or a denial-of-service.
Why this severity
The vulnerability is rated critical (CVSS 9.3) because it allows a low‑privilege local attacker to gain high impact on confidentiality, integrity, and availability of the SQL Server without needing user interaction.
What to do about it
- ›Disable the local caching feature that uses SQLite if it is not required.
- ›Switch from SQL Server authentication to Windows (trusted) authentication so credentials are not stored in plaintext.
- ›Restrict local access to the affected systems to trusted administrators only.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources; mitigations derived from the conditions described in the NVD description.
Timeline
- Apr 8, 2026 · Apr 8, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 24, 2026 · 11d agoAdvisory updatedThe NVD record was last revised.