CVE-2025-14816
Last modified
CVE-2025-14816 is a critical-severity vulnerability rated 9.3/10 on the CVSS scale. Cleartext Storage of Sensitive Information in GUI vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric AnalytiX versions 10.97.3 and prior, Mitsubishi Electric GENESIS versions 11.02 and prior, Mitsubishi Electric MC Works64 all versions, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions AnalytiX versions 10.97.3 and prior, and Mitsubishi Electric Iconics Digital Solutions GENESIS versions 11.02 and prior allows a local attacker to disclose the SQL Server credentials displayed in plain text in the GUI of the Hyper Historian Splitter feature by exploiting this vulnerability, when SQL authentication is used for the SQL Server authentication. As a result, the unauthorized attacker could access the SQL Server and disclose, tamper with, or destroy data on the server, potentially cause a denial-of-service (DoS) condition on the system.. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
Cleartext Storage of Sensitive Information in GUI vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric AnalytiX versions 10.97.3 and prior, Mitsubishi Electric GENESIS versions 11.02 and prior, Mitsubishi Electric MC Works64 all versions, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions MobileHMI versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions AnalytiX versions 10.97.3 and prior, and Mitsubishi Electric Iconics Digital Solutions GENESIS versions 11.02 and prior allows a local attacker to disclose the SQL Server credentials displayed in plain text in the GUI of the Hyper Historian Splitter feature by exploiting this vulnerability, when SQL authentication is used for the SQL Server authentication. As a result, the unauthorized attacker could access the SQL Server and disclose, tamper with, or destroy data on the server, potentially cause a denial-of-service (DoS) condition on the system.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Mitsubishi Electric Corporation | GENESIS64 | versions 10.97.3 and prior |
| Mitsubishi Electric Iconics Digital Solutions | GENESIS64 | versions 10.97.3 and prior |
| Mitsubishi Electric Corporation | ICONICS Suite | versions 10.97.3 and prior |
| Mitsubishi Electric Iconics Digital Solutions | ICONICS Suite | versions 10.97.3 and prior |
| Mitsubishi Electric Corporation | MobileHMI | versions 10.97.3 and prior |
| Mitsubishi Electric Iconics Digital Solutions | MobileHMI | versions 10.97.3 and prior |
| Mitsubishi Electric Corporation | Hyper Historian | versions 10.97.3 and prior |
| Mitsubishi Electric Iconics Digital Solutions | Hyper Historian | versions 10.97.3 and prior |
| Mitsubishi Electric Corporation | AnalytiX | versions 10.97.3 and prior |
| Mitsubishi Electric Iconics Digital Solutions | AnalytiX | versions 10.97.3 and prior |
| Mitsubishi Electric Corporation | GENESIS | versions 11.02 and prior |
| Mitsubishi Electric Iconics Digital Solutions | GENESIS | versions 11.02 and prior |
| Mitsubishi Electric Corporation | MC Works64 | all versions |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2025-14816?
How severe is CVE-2025-14816?
How do I fix CVE-2025-14816?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-1481The Shortcode Cleaner Lite plugin for WordPress is vulnerabl…4.3
- CVE-2025-14810IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 …6.5
- CVE-2025-14811IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.…5.9
- CVE-2025-14812ArcSearch for iOS versions prior to 1.45.2 could display a d…7.5
- CVE-2025-14813: Use of a Broken or Risky Cryptographic Algorithm vulnerabi…9.3
- CVE-2025-14815Cleartext Storage of Sensitive Information vulnerability in …9.3
- CVE-2025-14817The component com.transsion.tranfacmode.entrance.main.MainAc…6.5
- CVE-2025-14819When doing TLS related transfers with reused easy or multi h…5.3
- CVE-2025-14820Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2025-14821A flaw was found in libssh. This vulnerability allows local …7
- CVE-2025-14822Mattermost versions 10.11.x <= 10.11.8 fail to validate inpu…6.5
- CVE-2025-14823In deployments using the ScreenConnect™ Certificate Signing …5.3
Are you affected by CVE-2025-14816?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
