PT-2026-30801 · Mitsubishi · Analytix+6

CVE-2025-14815

·

Published

2026-04-07

·

Updated

2026-04-09

CVSS v4.0

9.3

Critical

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Mitsubishi Electric GENESIS64 versions prior to 10.97.3 Mitsubishi Electric ICONICS Suite versions prior to 10.97.3 Mitsubishi Electric MobileHMI versions prior to 10.97.3 Mitsubishi Electric Hyper Historian versions prior to 10.97.3 Mitsubishi Electric AnalytiX versions prior to 10.97.3 Mitsubishi Electric GENESIS versions prior to 11.02 Mitsubishi Electric MC Works64 (affected versions not specified) Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions prior to 10.97.3 Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions prior to 10.97.3 Mitsubishi Electric Iconics Digital Solutions MobileHMI versions prior to 10.97.3 Mitsubishi Electric Iconics Digital Solutions Hyper Historian versions prior to 10.97.3 Mitsubishi Electric Iconics Digital Solutions AnalytiX versions prior to 10.97.3 Mitsubishi Electric Iconics Digital Solutions GENESIS versions prior to 11.02
Description Sensitive information is stored in cleartext, allowing a local attacker to disclose SQL Server credentials stored within a local SQLite file. This occurs when the local caching feature using SQLite is enabled and SQL authentication is used for the SQL Server. An unauthorized attacker could leverage this to access the SQL Server to disclose, tamper with, or destroy data, potentially leading to a denial-of-service (DoS) condition, which is a state where a system becomes unavailable to its intended users.
Recommendations As a temporary workaround, disable the local caching feature using SQLite or avoid using SQL authentication for the SQL Server authentication. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-14815

Affected Products

Analytix
Genesis
Genesis64
Hyper Historian
Iconics Suite
Mc Works64
Mobilehmi