<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>M800VW - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/m800vw/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 27 Aug 2026 16:06:18 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/m800vw/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service Vulnerability in Mitsubishi Electric CNC Series</title><link>https://feed.craftedsignal.io/briefs/2026-08-mitsubishi-cnc-dos/</link><pubDate>Thu, 27 Aug 2026 16:06:18 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-mitsubishi-cnc-dos/</guid><description>An out-of-bounds read vulnerability (CVE-2025-2399) in Mitsubishi Electric CNC Series controllers allows remote attackers to trigger a denial-of-service condition via crafted packets sent to TCP port 683.</description><content:encoded><![CDATA[<p>Mitsubishi Electric has disclosed a vulnerability (CVE-2025-2399) affecting multiple versions of its CNC Series controllers, including the M800V, M80V, M800, M80, E80, C80, and M70 series. The vulnerability is rooted in improper validation of indices, positions, or offsets (CWE-1285) within the input processing logic of the affected devices.</p>
<p>By sending specially crafted packets to TCP port 683, a remote attacker can induce an out-of-bounds read, resulting in a denial-of-service (DoS) condition. This vulnerability poses a risk to critical manufacturing environments where these CNC controllers are deployed. Defenders should focus on isolating affected hardware from untrusted networks and restricting access to TCP port 683. Patches are available from Mitsubishi Electric, and organizations should prioritize updates to the specified versions (BC, FN, or LK, depending on the product series) or apply the recommended IP filtering and network segmentation mitigations.</p>
<h2 id="impact">Impact</h2>
<p>The successful exploitation of CVE-2025-2399 results in a denial-of-service, which in an industrial manufacturing context can lead to unplanned downtime, loss of production, and disruption of automated machining processes. The vulnerability is rated with a CVSS 3.1 score of 5.9 (Medium), reflecting that while exploitation is remote, it requires specific technical craft to trigger the DoS condition. The affected devices are deployed globally in the critical manufacturing sector.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Apply the vendor-provided firmware updates (version BC, FN, or LK) appropriate for the specific CNC controller model.</li>
<li>Isolate CNC controller networks from the enterprise network using firewalls or VPNs to prevent unauthorized access to TCP port 683.</li>
<li>Implement IP address filtering on the affected controllers using the manufacturer's built-in functions to restrict communication to known-authorized endpoints.</li>
<li>Restrict physical access to CNC hardware and connected network infrastructure.</li>
<li>Deploy network intrusion detection systems to alert on abnormal traffic patterns directed at TCP port 683.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>ics</category><category>dos</category><category>industrial-control-systems</category><category>critical-infrastructure</category><category>cve-2025-2399</category></item></channel></rss>