{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/mitsubishi-electric/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["M800VW","M800VS","M80V","M80VW","M800W","M800S","M80","M80W","E80","C80","M750VW","M730VW","M720VW","M750VS","M730VS","M720VS","M70V","E70"],"_cs_severities":["medium"],"_cs_tags":["ics","dos","industrial-control-systems","critical-infrastructure","cve-2025-2399"],"_cs_type":"advisory","_cs_vendors":["Mitsubishi Electric"],"content_html":"\u003cp\u003eMitsubishi Electric has disclosed a vulnerability (CVE-2025-2399) affecting multiple versions of its CNC Series controllers, including the M800V, M80V, M800, M80, E80, C80, and M70 series. The vulnerability is rooted in improper validation of indices, positions, or offsets (CWE-1285) within the input processing logic of the affected devices.\u003c/p\u003e\n\u003cp\u003eBy sending specially crafted packets to TCP port 683, a remote attacker can induce an out-of-bounds read, resulting in a denial-of-service (DoS) condition. This vulnerability poses a risk to critical manufacturing environments where these CNC controllers are deployed. Defenders should focus on isolating affected hardware from untrusted networks and restricting access to TCP port 683. Patches are available from Mitsubishi Electric, and organizations should prioritize updates to the specified versions (BC, FN, or LK, depending on the product series) or apply the recommended IP filtering and network segmentation mitigations.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2025-2399 results in a denial-of-service, which in an industrial manufacturing context can lead to unplanned downtime, loss of production, and disruption of automated machining processes. The vulnerability is rated with a CVSS 3.1 score of 5.9 (Medium), reflecting that while exploitation is remote, it requires specific technical craft to trigger the DoS condition. The affected devices are deployed globally in the critical manufacturing sector.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the vendor-provided firmware updates (version BC, FN, or LK) appropriate for the specific CNC controller model.\u003c/li\u003e\n\u003cli\u003eIsolate CNC controller networks from the enterprise network using firewalls or VPNs to prevent unauthorized access to TCP port 683.\u003c/li\u003e\n\u003cli\u003eImplement IP address filtering on the affected controllers using the manufacturer's built-in functions to restrict communication to known-authorized endpoints.\u003c/li\u003e\n\u003cli\u003eRestrict physical access to CNC hardware and connected network infrastructure.\u003c/li\u003e\n\u003cli\u003eDeploy network intrusion detection systems to alert on abnormal traffic patterns directed at TCP port 683.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T16:06:18Z","date_published":"2026-08-27T16:06:18Z","id":"https://feed.craftedsignal.io/briefs/2026-08-mitsubishi-cnc-dos/","summary":"An out-of-bounds read vulnerability (CVE-2025-2399) in Mitsubishi Electric CNC Series controllers allows remote attackers to trigger a denial-of-service condition via crafted packets sent to TCP port 683.","title":"Denial of Service Vulnerability in Mitsubishi Electric CNC Series","url":"https://feed.craftedsignal.io/briefs/2026-08-mitsubishi-cnc-dos/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2025-3511"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CC-Link IE TSN Remote I/O module (\u003c=09)","CC-Link IE TSN Analog-Digital Converter module (\u003c=07)","CC-Link IE TSN Digital-Analog Converter module (\u003c=07)","CC-Link IE TSN FPGA module (01)","CC-Link IE TSN Remote Station Communication LSI CP620 (\u003c=1.08J)","MELSEC iQ-R Series CC-Link IE TSN Master/Local Module (\u003c=26)","MELSEC iQ-R Series Ethernet Interface Module (\u003c=85)","CC-Link IE TSN master/local Station Communication LSI CP610 (\u003c=05)","MELSEC iQ-F Series FX5 CC-Link IE TSN Master/Local Module (\u003c=1.020)","MELSEC iQ-F Series FX5 Ethernet Module (\u003c=1.200)","MELSEC iQ-F Series FX5-ENET/IP Ethernet Module (\u003c=1.106)","MELSEC iQ-R Series CPU module (Network Part) (\u003c=85)"],"_cs_severities":["low"],"_cs_tags":["industrial-control-systems","denial-of-service","cve-2025-3511"],"_cs_type":"advisory","_cs_vendors":["Mitsubishi Electric"],"content_html":"\u003cp\u003eMitsubishi Electric has disclosed a high-severity vulnerability (CVE-2025-3511) affecting a wide array of Factory Automation (FA) products, including CC-Link IE TSN modules, MELSEC iQ-R series, and MELSEC iQ-F series controllers. The issue stems from Improper Validation of Specified Quantity in Input (CWE-1284) within the devices' Ethernet communication stack. By sending a specially crafted UDP packet to an affected device, a remote, unauthenticated attacker can induce a denial-of-service (DoS) condition, communication timeouts, or significant latency. Depending on the specific product, recovery requires a system reset or the resumption of valid UDP traffic. Given the deployment of these industrial control components within the critical manufacturing sector, this vulnerability poses a risk to operational availability and process continuity. Defenders should identify vulnerable assets within their OT networks and apply vendor-supplied firmware updates where available.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability impacts industrial control system infrastructure globally within the critical manufacturing sector. Successful exploitation results in a loss of network communication for critical I/O modules, CPUs, and interface modules. In many cases, a hardware reset is required to restore normal operations, which could lead to unplanned downtime and disruption of manufacturing processes.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all affected Mitsubishi Electric FA hardware using the provided product list and ensure internal inventory reflects the specified vulnerable firmware versions.\u003c/li\u003e\n\u003cli\u003eImplement network segmentation to isolate industrial Ethernet traffic, restricting access to these devices from untrusted network segments.\u003c/li\u003e\n\u003cli\u003eMonitor for anomalous UDP traffic patterns originating from unauthorized sources directed toward industrial Ethernet interfaces.\u003c/li\u003e\n\u003cli\u003ePrioritize firmware updates as provided by Mitsubishi Electric to address CVE-2025-3511 across the entire affected product line.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-27T16:05:55Z","date_published":"2026-08-27T16:05:55Z","id":"https://feed.craftedsignal.io/briefs/2026-08-mitsubishi-fa-dos/","summary":"A vulnerability in the Ethernet function of multiple Mitsubishi Electric factory automation products allows remote attackers to trigger a denial-of-service condition via specially crafted UDP packets.","title":"Denial of Service Vulnerability in Mitsubishi Electric FA Products","url":"https://feed.craftedsignal.io/briefs/2026-08-mitsubishi-fa-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Mitsubishi Electric","version":"https://jsonfeed.org/version/1.1"}