[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fUTp-01AW2zH-i2QJ3E-WKl-bjc-fr-EqcgqoWcSzYCc":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"8ccda10b-9c78-407c-8e63-ea9b0d8ac6e4","mitsubishi-electric-industrial-software-exposes-sql-credentials-in-cleartext","5a93327c-a630-4e86-b658-f30d453f57af","Mitsubishi Electric Industrial Software Exposes SQL Credentials in Cleartext","Two high-severity vulnerabilities in Mitsubishi Electric's industrial software products store SQL Server credentials in plaintext within SQLite cache files and GUI displays. Local attackers can easily extract these credentials to compromise databases or disrupt industrial operations. This demonstrates a fundamental failure in credential protection that puts critical infrastructure at risk. While patches are available for most products, MC Works 64 remains unpatched, highlighting the importance of having migration plans for unsupported systems.","**Immediate actions:**\n- Update all affected Mitsubishi Electric products to version 10.98 or 11.03 where patches are available\n- Review and rotate all SQL Server credentials that may have been exposed\n- Implement database access monitoring to detect unauthorized credential usage\n\n**Long-term improvements:**\n- Establish encrypted credential storage policies for all industrial control systems\n- Create migration plans for end-of-life products like MC Works 64 that no longer receive security updates\n- Implement network segmentation to limit local access to industrial software systems\n\n**Detection measures:**\n- Deploy file integrity monitoring on systems storing sensitive credentials\n- Enable SQL Server audit logging to track credential usage and potential compromise",[12,13,14,15,16],"CIS Control 3.3","CIS Control 7.1","NIST SP 800-53 IA-5","NIST SP 800-82 SC-8","IEC 62443-3-3 SR 1.1","published","2026-04-07T21:09:48.341146+00:00","2026-04-07T21:09:48.213+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-097-01","mitsubishi-electric-genesis64-and-iconics-suite-products","Mitsubishi Electric GENESIS64 and ICONICS Suite products",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":32,"name":33,"slug":34,"description":35,"color":36},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]