OVERVIEW CVE-2025-14816 is a cleartext storage vulnerability affecting multiple Mitsubishi Electric industrial control and human-machine interface (HMI) products, including GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, GENESIS, and MC Works64. The vulnerability exposes SQL Server credentials in plain text within the GUI of the Hyper Historian Splitter feature when SQL authentication is configured. Affected versions include Mitsubishi Electric and Iconics Digital Solutions product lines at version 10.97.3 and prior, with GENESIS affected at version 11.02 and prior. SEVERITY The vulnerability requires local access to exploit, representing a moderate attack complexity. A successful exploitation enables unauthorized access to SQL Server systems, potentially allowing adversaries to disclose, modify, or destroy sensitive operational data. The attack could also facilitate denial-of-service conditions against critical infrastructure systems that rely on these HMI and industrial automation platforms for operational visibility and control. EXPLOITATION STATUS CVE-2025-14816 is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog, indicating no confirmed active exploitation in the wild. The vulnerability remains inactive on security community hot lists, suggesting limited public attention and no readily available proof-of-concept code. However, organizations operating these Mitsubishi Electric products should prioritize remediation given the straightforward nature of the vulnerability and potential access to critical industrial control environments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Mitsubishi Electric Corporation | AnalytiX | versions 10.97.3 and priorCNA affecteddefault unaffected | |
| Mitsubishi Electric Iconics Digital Solutions | AnalytiX | versions 10.97.3 and priorCNA affecteddefault unaffected | |
| Mitsubishi Electric Corporation | GENESIS | versions 11.02 and priorCNA affecteddefault unaffected | |
| Mitsubishi Electric Iconics Digital Solutions | GENESIS | versions 11.02 and priorCNA affecteddefault unaffected | |
| Mitsubishi Electric Corporation | GENESIS64 | versions 10.97.3 and priorCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.8 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.