SCADA Flaw Enables DoS Condition, Impacting Availability of Affected Systems
ID: 022e32b1-0ff3-5793-bdc3-943817a9eaef
STIX ID: report--022e32b1-0ff3-5793-bdc3-943817a9eaef
Feed Name: GBHackers
A medium-severity vulnerability (CVE-2025-0921, CVSS 6.5) in the Mitsubishi Electric Iconics GENESIS64 AlarmWorX64 MMX Pager Agent lets local non-admin users redirect logging to critical system files (via the SMSLogFile path) and, when combined with a separate permission misconfiguration (CVE-2024-7587), can overwrite Windows drivers such as cng.sys causing boot failures and persistent DoS of OT engineering workstations; vendor advisories and mitigations are available and affected systems (Iconics Suite 10.97.2 and earlier) should be patched immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
