Local Access to HMI Can Expose Plant SQL Databases

Mitsubishi Electric GENESIS64, ICONICS Suite, and related products store SQL Server credentials in plaintext on local hosts when SQLite caching and SQL authentication are enabled. This means a local attacker who gains access to an operator or engineering workstation can extract these credentials and use them to access, tamper with, or disrupt plant databases that feed dashboards, historians, and potentially control systems. The affected products include GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, MC Works 64, and GENESIS, with vulnerable versions up to 10.97.3 or 11.02 depending on the product. This is not just a local compromise risk; it can lead to broader data integrity and availability failures across the plant if SQL credentials are reused. The advisory from CISA highlights the wide blast radius of this credential disclosure vulnerability in critical manufacturing environments. Operators should verify and assess exposure, especially where local access to these

Part of the PlainSec briefing for 2026-04-08

Sources