{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/tension-meter-all-versions/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-13584"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MELSEC MX Controller (all versions)","Master/local module (all versions)","CC-Link IE TSN interface board (all versions)","Motion module (all versions)","MELSEC iQ-L Series Motion Module (all versions)","Motion Control Board (all versions)","Block-type remote module (all versions)","Analog-Digital converter module (all versions)","Digital-Analog converter module (all versions)","CC-Link IE TSN compatible coupler (all versions)","FPGA module (all versions)","Tension meter (all versions)","AC Servo MELSERVO-J5 (all versions)","AC Servo MELSERVO-JET (all versions)","Liner Track System MTR-S series (all versions)","Inverter FR-A800/F800/E800 Series (all versions)","Industrial Robot CR800-D series (all versions)","CC-Link IE TSN expansion unit (all versions)","CC-Link IE TSN-CC-Link IE Field Network bridge module (all versions)","CC-Link IE TSN-AnyWireASLINK bridge module (all versions)","Energy Measuring Unit CC-Link IE TSN Communication Unit (all versions)","GOT3000 Series (all versions)","CC-Link IE TSN Communication Unit (all versions)","Motion Control Software (all versions)","CC-Link IE TSN Communication Software for Windows (all versions)","Analysis Support Software MELSOFT VIMA (all versions)","Master/Local module Designated communication LSI DeviceKit (all versions)","Remote Station Communication LSI with GbE-PHY (all versions)"],"_cs_severities":["medium"],"_cs_tags":["ics","ot","vulnerability","cve-2026-13584"],"_cs_type":"advisory","_cs_vendors":["Mitsubishi Electric"],"content_html":"\u003cp\u003eMitsubishi Electric has identified a significant vulnerability (CVE-2026-13584) affecting a wide range of industrial automation products utilizing the CC-Link IE TSN communication protocol. This vulnerability exists in the protocol's handling of network traffic, specifically related to the timing of packet processing. An attacker with access to the same local network segment as the target device can leverage this flaw by injecting specially crafted packets under precise timing conditions.\u003c/p\u003e\n\u003cp\u003eIf successful, the exploitation results in the interference of the device's primary control functions. This can manifest as unauthorized tampering with process communication data or the triggering of a Denial-of-Service (DoS) condition, potentially causing the industrial equipment to operate incorrectly or cease functionality entirely. Given the broad ecosystem of affected hardware, including motion modules, servos, inverters, and industrial controllers, this vulnerability poses a critical operational risk to facilities relying on these components for time-sensitive industrial control.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability impacts a vast array of Mitsubishi Electric industrial assets, including the MELSEC iQ series, GOT3000 HMI series, and various motor control units. Successful exploitation can lead to a complete loss of control over industrial processes, potentially leading to equipment damage, process shutdowns, or safety-related disruptions in production environments. Organizations utilizing these products within their Operational Technology (OT) networks are advised to restrict network access to affected controllers and implement strict network segmentation to mitigate the risk of unauthorized traffic reaching the CC-Link IE TSN network segment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement strict network segmentation to ensure that only authorized devices have access to the CC-Link IE TSN network segment.\u003c/li\u003e\n\u003cli\u003eMonitor for anomalous industrial network traffic patterns, specifically focusing on malformed or out-of-sequence packets directed at CC-Link IE TSN-enabled interfaces.\u003c/li\u003e\n\u003cli\u003eReview the official Mitsubishi Electric security bulletin for specific patch availability or configuration hardening steps for each identified product model.\u003c/li\u003e\n\u003cli\u003eLimit physical and logical access to the network infrastructure supporting these industrial assets to mitigate the requirement for local segment access.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-17T17:10:57Z","date_published":"2026-09-17T17:10:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-mitsubishi-cc-link-tsn/","summary":"A vulnerability in the Mitsubishi Electric CC-Link IE TSN Communication Protocol (CVE-2026-13584) allows network-adjacent attackers to disrupt control functions or tamper with data via specially crafted packets.","title":"Mitsubishi Electric CC-Link IE TSN Communication Protocol Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-mitsubishi-cc-link-tsn/"}],"language":"en","title":"CraftedSignal Threat Feed - Tension Meter (All Versions)","version":"https://jsonfeed.org/version/1.1"}