Uncontrolled Search Path Element vulnerability in ICONICS GENESIS64 all versions, Mitsubishi Electric GENESIS64 all versions and Mitsubishi Electric MC Works64 all versions allows a local authenticated attacker to execute a malicious code by storing a specially crafted DLL in a specific folder. This could lead to disclose, tamper with, destroy, or delete information in the affected products, or cause a denial of service (DoS) condition on the products.
https://cyberscoop.com/iconics-scada-vulnerabilities-2025-palo-alto/
https://unit42.paloaltonetworks.com/vulnerabilities-in-iconics-software-suite/
https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-04
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-010_en.pdf