Iconics develops industrial automation and control software across a portfolio of visualization, data collection, and human-machine interface products including Genesis64, Genesis32, BizViz, and Hyper Historian, platforms widely deployed in manufacturing and critical infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency to acquire public exploit code reflecting the operational-technology environment's appeal as a high-value target. The exposure recurs through weakness classes centered on deserialization of untrusted data, path traversal, and memory-safety issues—challenges inherent to legacy OT software architectures and remote-access components. Defenders operating these platforms should prioritize network segmentation and monitor for exploitation of publicly available attack tooling; current exploitation activity and severity distribution are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iconics over time
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-2089HIGH Stack-based buffer overflow in the SetActiveXGUID method in the VersionInfo ActiveX control in GenVersion.dll 8.0.138.0 in the WebHMI subsystem in ICONICS BizViz 9.x before 9.22 an | May 13, 2011 | 9.3 | 67 | NO | YES |
CVE-2022-33318CRITICAL Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 t | Jul 20, 2022 | 9.8 | 56 | NO | NO |
CVE-2020-12011CRITICAL A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition or allow remote code execution. This issue affects: Mitsubishi Elect | Jul 16, 2020 | 9.8 | 38 | NO | NO |
CVE-2022-23128CRITICAL Incomplete List of Disallowed Inputs vulnerability in Mitsubishi Electric MC Works64 versions 4.00A (10.95.201.23) to 4.04E (10.95.210.01), ICONICS GENESIS64 versions 10.95.3 to 10 | Jan 21, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-12007CRITICAL A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-service condition due to a deserialization vulnerability. Th | Jul 16, 2020 | 9.8 | 31 | NO | NO |
CVE-2006-6488HIGH Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used by ICONICS OPC Enabled Gauge, Switch, an | Dec 31, 2006 | 7.5 | 31 | NO | YES |
CVE-2020-12013CRITICAL A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely. This affects: Mitsubishi Electric MC Works64 Version 4.02C | Jul 16, 2020 | 9.1 | 30 | NO | NO |
CVE-2011-5089HIGH Buffer overflow in the Security Login ActiveX controls in ICONICS GENESIS32 8.05, 9.0, 9.1, and 9.2 and BizViz 8.05, 9.0, 9.1, and 9.2 allows remote attackers to cause a denial of | Apr 18, 2012 | 10.0 | 30 | NO | NO |
CVE-2022-33319CRITICAL Out-of-bounds Read vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mits | Jul 20, 2022 | 9.1 | 28 | NO | NO |
CVE-2014-0758HIGH An ActiveX control in GenLaunch.htm in ICONICS GENESIS32 8.0, 8.02, 8.04, and 8.05 allows remote attackers to execute arbitrary programs via a crafted HTML document. | Feb 24, 2014 | 9.3 | 28 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iconics.
Media articles that mention a CVE ID that affects a product developed by Iconics — matched by CVE ID, not by vendor name.