Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Iconics

First CVE: Dec 31, 2006Active for: 20 yearsTotal CVEs: 27
46.6
VTI Score
High

Iconics develops industrial automation and control software across a portfolio of visualization, data collection, and human-machine interface products including Genesis64, Genesis32, BizViz, and Hyper Historian, platforms widely deployed in manufacturing and critical infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency to acquire public exploit code reflecting the operational-technology environment's appeal as a high-value target. The exposure recurs through weakness classes centered on deserialization of untrusted data, path traversal, and memory-safety issues—challenges inherent to legacy OT software architectures and remote-access components. Defenders operating these platforms should prioritize network segmentation and monitor for exploitation of publicly available attack tooling; current exploitation activity and severity distribution are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Iconics over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2006
19 years ago
Most Recent CVE
Oct 22, 2024
640 days ago

Products(12 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2011-2089HIGH
Stack-based buffer overflow in the SetActiveXGUID method in the VersionInfo ActiveX control in GenVersion.dll 8.0.138.0 in the WebHMI subsystem in ICONICS BizViz 9.x before 9.22 an
May 13, 20119.367NOYES
CVE-2022-33318CRITICAL
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 t
Jul 20, 20229.856NONO
CVE-2020-12011CRITICAL
A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition or allow remote code execution. This issue affects: Mitsubishi Elect
Jul 16, 20209.838NONO
CVE-2022-23128CRITICAL
Incomplete List of Disallowed Inputs vulnerability in Mitsubishi Electric MC Works64 versions 4.00A (10.95.201.23) to 4.04E (10.95.210.01), ICONICS GENESIS64 versions 10.95.3 to 10
Jan 21, 20229.831NONO
CVE-2020-12007CRITICAL
A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-service condition due to a deserialization vulnerability. Th
Jul 16, 20209.831NONO
CVE-2006-6488HIGH
Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used by ICONICS OPC Enabled Gauge, Switch, an
Dec 31, 20067.531NOYES
CVE-2020-12013CRITICAL
A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely. This affects: Mitsubishi Electric MC Works64 Version 4.02C
Jul 16, 20209.130NONO
CVE-2011-5089HIGH
Buffer overflow in the Security Login ActiveX controls in ICONICS GENESIS32 8.05, 9.0, 9.1, and 9.2 and BizViz 8.05, 9.0, 9.1, and 9.2 allows remote attackers to cause a denial of
Apr 18, 201210.030NONO
CVE-2022-33319CRITICAL
Out-of-bounds Read vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mits
Jul 20, 20229.128NONO
CVE-2014-0758HIGH
An ActiveX control in GenLaunch.htm in ICONICS GENESIS32 8.0, 8.02, 8.04, and 8.05 allows remote attackers to execute arbitrary programs via a crafted HTML document.
Feb 24, 20149.328NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
15%
59%
22%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local10 (37.0%)
Network11 (40.7%)
Unknown6 (22.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (77.8%)
High0 (0.0%)
Unknown6 (22.2%)
User Interaction
None12 (44.4%)
Unknown6 (22.2%)
Required9 (33.3%)
Privileges Required
Low2 (7.4%)
High0 (0.0%)
None19 (70.4%)
Unknown6 (22.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
3.7% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
7.4% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Iconics.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Iconics — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Iconics's Products

View all 4 CNAs →

Top CWEs