<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Digital-Analog Converter Module (All Versions) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/digital-analog-converter-module-all-versions/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 17 Sep 2026 17:10:57 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/digital-analog-converter-module-all-versions/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Mitsubishi Electric CC-Link IE TSN Communication Protocol Vulnerability</title><link>https://feed.craftedsignal.io/briefs/2026-09-mitsubishi-cc-link-tsn/</link><pubDate>Thu, 17 Sep 2026 17:10:57 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-mitsubishi-cc-link-tsn/</guid><description>A vulnerability in the Mitsubishi Electric CC-Link IE TSN Communication Protocol (CVE-2026-13584) allows network-adjacent attackers to disrupt control functions or tamper with data via specially crafted packets.</description><content:encoded><![CDATA[<p>Mitsubishi Electric has identified a significant vulnerability (CVE-2026-13584) affecting a wide range of industrial automation products utilizing the CC-Link IE TSN communication protocol. This vulnerability exists in the protocol's handling of network traffic, specifically related to the timing of packet processing. An attacker with access to the same local network segment as the target device can leverage this flaw by injecting specially crafted packets under precise timing conditions.</p>
<p>If successful, the exploitation results in the interference of the device's primary control functions. This can manifest as unauthorized tampering with process communication data or the triggering of a Denial-of-Service (DoS) condition, potentially causing the industrial equipment to operate incorrectly or cease functionality entirely. Given the broad ecosystem of affected hardware, including motion modules, servos, inverters, and industrial controllers, this vulnerability poses a critical operational risk to facilities relying on these components for time-sensitive industrial control.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability impacts a vast array of Mitsubishi Electric industrial assets, including the MELSEC iQ series, GOT3000 HMI series, and various motor control units. Successful exploitation can lead to a complete loss of control over industrial processes, potentially leading to equipment damage, process shutdowns, or safety-related disruptions in production environments. Organizations utilizing these products within their Operational Technology (OT) networks are advised to restrict network access to affected controllers and implement strict network segmentation to mitigate the risk of unauthorized traffic reaching the CC-Link IE TSN network segment.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Implement strict network segmentation to ensure that only authorized devices have access to the CC-Link IE TSN network segment.</li>
<li>Monitor for anomalous industrial network traffic patterns, specifically focusing on malformed or out-of-sequence packets directed at CC-Link IE TSN-enabled interfaces.</li>
<li>Review the official Mitsubishi Electric security bulletin for specific patch availability or configuration hardening steps for each identified product model.</li>
<li>Limit physical and logical access to the network infrastructure supporting these industrial assets to mitigate the requirement for local segment access.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>ics</category><category>ot</category><category>vulnerability</category><category>cve-2026-13584</category></item></channel></rss>