{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/m730vs/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["M800VW","M800VS","M80V","M80VW","M800W","M800S","M80","M80W","E80","C80","M750VW","M730VW","M720VW","M750VS","M730VS","M720VS","M70V","E70"],"_cs_severities":["medium"],"_cs_tags":["ics","dos","industrial-control-systems","critical-infrastructure","cve-2025-2399"],"_cs_type":"advisory","_cs_vendors":["Mitsubishi Electric"],"content_html":"\u003cp\u003eMitsubishi Electric has disclosed a vulnerability (CVE-2025-2399) affecting multiple versions of its CNC Series controllers, including the M800V, M80V, M800, M80, E80, C80, and M70 series. The vulnerability is rooted in improper validation of indices, positions, or offsets (CWE-1285) within the input processing logic of the affected devices.\u003c/p\u003e\n\u003cp\u003eBy sending specially crafted packets to TCP port 683, a remote attacker can induce an out-of-bounds read, resulting in a denial-of-service (DoS) condition. This vulnerability poses a risk to critical manufacturing environments where these CNC controllers are deployed. Defenders should focus on isolating affected hardware from untrusted networks and restricting access to TCP port 683. Patches are available from Mitsubishi Electric, and organizations should prioritize updates to the specified versions (BC, FN, or LK, depending on the product series) or apply the recommended IP filtering and network segmentation mitigations.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2025-2399 results in a denial-of-service, which in an industrial manufacturing context can lead to unplanned downtime, loss of production, and disruption of automated machining processes. The vulnerability is rated with a CVSS 3.1 score of 5.9 (Medium), reflecting that while exploitation is remote, it requires specific technical craft to trigger the DoS condition. The affected devices are deployed globally in the critical manufacturing sector.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the vendor-provided firmware updates (version BC, FN, or LK) appropriate for the specific CNC controller model.\u003c/li\u003e\n\u003cli\u003eIsolate CNC controller networks from the enterprise network using firewalls or VPNs to prevent unauthorized access to TCP port 683.\u003c/li\u003e\n\u003cli\u003eImplement IP address filtering on the affected controllers using the manufacturer's built-in functions to restrict communication to known-authorized endpoints.\u003c/li\u003e\n\u003cli\u003eRestrict physical access to CNC hardware and connected network infrastructure.\u003c/li\u003e\n\u003cli\u003eDeploy network intrusion detection systems to alert on abnormal traffic patterns directed at TCP port 683.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T16:06:18Z","date_published":"2026-08-27T16:06:18Z","id":"https://feed.craftedsignal.io/briefs/2026-08-mitsubishi-cnc-dos/","summary":"An out-of-bounds read vulnerability (CVE-2025-2399) in Mitsubishi Electric CNC Series controllers allows remote attackers to trigger a denial-of-service condition via crafted packets sent to TCP port 683.","title":"Denial of Service Vulnerability in Mitsubishi Electric CNC Series","url":"https://feed.craftedsignal.io/briefs/2026-08-mitsubishi-cnc-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - M730VS","version":"https://jsonfeed.org/version/1.1"}