Close Menu
    Main Menu
    • Home
    • News
    • Tech
    • Robotics
    • ML & Research
    • AI
    • Digital Transformation
    • AI Ethics & Regulation
    • Thought Leadership in AI

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Key Capabilities and Pricing Defined

    March 13, 2026

    Why Monitoring Issues In 2026

    March 13, 2026

    Greatest Android Smartwatch for 2026

    March 13, 2026
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Facebook X (Twitter) Instagram
    UK Tech InsiderUK Tech Insider
    Home»AI Ethics & Regulation»SCADA Flaw Allows DoS Situation, Impacting Availability of Affected Methods
    AI Ethics & Regulation

    SCADA Flaw Allows DoS Situation, Impacting Availability of Affected Methods

    Declan MurphyBy Declan MurphyJanuary 31, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    SCADA Flaw Allows DoS Situation, Impacting Availability of Affected Methods
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link


    A vulnerability affecting the Mitsubishi Electrical Iconics Suite, a broadly deployed supervisory management and knowledge acquisition (SCADA) system used throughout industrial sectors, together with automotive, power, and manufacturing.

    The flaw, tracked as CVE-2025-0921, carries a CVSS rating of 6.5 (Medium severity) and allows attackers to set off denial-of-service (DoS) circumstances on affected methods, compromising operational availability.

    Vulnerability Overview

    CVE Identifier Vulnerability Description CVSS Rating
    CVE-2025-0921 Execution with pointless privileges vulnerability in a number of providers of Mitsubishi Electrical Iconics Digital Options GENESIS64 6.5 – Medium

    In keeping with Paloalto Community, the vulnerability stems from privileged file system operations inside the Iconics Suite’s AlarmWorX64 MMX Pager Agent element.

    When exploited, attackers with native non-administrative entry can manipulate essential system binaries, resulting in system corruption and rendering industrial management methods inoperable.

    The flaw impacts Microsoft Home windows variations 10.97.2 and earlier of the Iconics Suite.

    CVE-2025-0921 permits menace actors to misuse privileged file system operations by manipulating the SMSLogFile configuration path saved within the IcoSetup64.ini file.

    Permissions of GraphWorX64(supply: paloaltonetworks)

    Attackers can create symbolic hyperlinks redirecting logging operations to essential Home windows drivers equivalent to cng.sys, which offers cryptographic providers important for system boot processes.

    The exploitation turns into significantly efficient when mixed with CVE-2024-7587, a separate vulnerability within the GenBroker32 installer that grants extreme file permissions to the C:ProgramDataICONICS listing.

    This permission misconfiguration permits any native person to switch configuration recordsdata that ought to be restricted to directors.

    Assault Methodology

    In a proof-of-concept demonstration, researchers confirmed how an attacker with non-privileged entry might redirect SMS logging operations to overwrite the cng.sys driver.

    newly altered cng.sys file created by the exploit(source:PaloAltonetwork)
    newly altered cng.sys file created by the exploit(supply:PaloAltonetwork)

    By making a symbolic hyperlink from the configured SMSLogFile path to C:WindowsSystem32cng.sys, subsequent SMS alert operations corrupt the motive force file with log knowledge as an alternative of legitimate binary code.

    Upon system reboot, Home windows makes an attempt to load the corrupted driver, leading to boot failure and an infinite restore loop.

    This creates a persistent DoS situation on essential operational expertise (OT) engineering workstations, probably disrupting industrial monitoring and management operations.

    Endless Windows boot loop caused by the corrupted driver (source: paloaltonetworks)
    Infinite Home windows boot loop attributable to the corrupted driver (supply: paloaltonetworks)

    Mitsubishi Electrical has launched a safety advisory detailing remediation measures for CVE-2025-0921.

    System directors ought to instantly apply the really helpful workarounds, which deal with all vulnerabilities recognized within the Iconics Suite evaluation.

    Industrial organizations working Iconics Suite variations 10.97.2 and earlier ought to prioritize patching and implement the vendor-recommended safety controls to stop potential service disruptions.

    The vulnerability highlights the essential significance of correct entry controls and privilege administration in industrial management system environments the place availability is paramount.

    Comply with us on Google Information, LinkedIn, and X to Get Instantaneous Updates and Set GBH as a Most well-liked Supply in Google.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Declan Murphy
    • Website

    Related Posts

    Why Monitoring Issues In 2026

    March 13, 2026

    Feds Dismantle SocksEscort Proxy Community Utilized in World Fraud

    March 13, 2026

    Why Stryker’s Outage Is a Catastrophe Restoration Wake-Up Name

    March 13, 2026
    Top Posts

    Key Capabilities and Pricing Defined

    March 13, 2026

    Evaluating the Finest AI Video Mills for Social Media

    April 18, 2025

    Utilizing AI To Repair The Innovation Drawback: The Three Step Resolution

    April 18, 2025

    Midjourney V7: Quicker, smarter, extra reasonable

    April 18, 2025
    Don't Miss

    Key Capabilities and Pricing Defined

    By Amelia Harper JonesMarch 13, 2026

    From casual dialog to detailed roleplay and extra private material, KrushChat provides customers the chance…

    Why Monitoring Issues In 2026

    March 13, 2026

    Greatest Android Smartwatch for 2026

    March 13, 2026

    Ought to You Be Susceptible At Work?

    March 13, 2026
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    UK Tech Insider
    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms Of Service
    • Our Authors
    © 2026 UK Tech Insider. All rights reserved by UK Tech Insider.

    Type above and press Enter to search. Press Esc to cancel.