<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Mitsubishi Electric - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/mitsubishi-electric/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 27 Aug 2026 16:06:18 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/mitsubishi-electric/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Denial of Service Vulnerability in Mitsubishi Electric CNC Series</title><link>https://feed.craftedsignal.io/briefs/2026-08-mitsubishi-cnc-dos/</link><pubDate>Thu, 27 Aug 2026 16:06:18 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-mitsubishi-cnc-dos/</guid><description>An out-of-bounds read vulnerability (CVE-2025-2399) in Mitsubishi Electric CNC Series controllers allows remote attackers to trigger a denial-of-service condition via crafted packets sent to TCP port 683.</description><content:encoded><![CDATA[<p>Mitsubishi Electric has disclosed a vulnerability (CVE-2025-2399) affecting multiple versions of its CNC Series controllers, including the M800V, M80V, M800, M80, E80, C80, and M70 series. The vulnerability is rooted in improper validation of indices, positions, or offsets (CWE-1285) within the input processing logic of the affected devices.</p>
<p>By sending specially crafted packets to TCP port 683, a remote attacker can induce an out-of-bounds read, resulting in a denial-of-service (DoS) condition. This vulnerability poses a risk to critical manufacturing environments where these CNC controllers are deployed. Defenders should focus on isolating affected hardware from untrusted networks and restricting access to TCP port 683. Patches are available from Mitsubishi Electric, and organizations should prioritize updates to the specified versions (BC, FN, or LK, depending on the product series) or apply the recommended IP filtering and network segmentation mitigations.</p>
<h2 id="impact">Impact</h2>
<p>The successful exploitation of CVE-2025-2399 results in a denial-of-service, which in an industrial manufacturing context can lead to unplanned downtime, loss of production, and disruption of automated machining processes. The vulnerability is rated with a CVSS 3.1 score of 5.9 (Medium), reflecting that while exploitation is remote, it requires specific technical craft to trigger the DoS condition. The affected devices are deployed globally in the critical manufacturing sector.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Apply the vendor-provided firmware updates (version BC, FN, or LK) appropriate for the specific CNC controller model.</li>
<li>Isolate CNC controller networks from the enterprise network using firewalls or VPNs to prevent unauthorized access to TCP port 683.</li>
<li>Implement IP address filtering on the affected controllers using the manufacturer's built-in functions to restrict communication to known-authorized endpoints.</li>
<li>Restrict physical access to CNC hardware and connected network infrastructure.</li>
<li>Deploy network intrusion detection systems to alert on abnormal traffic patterns directed at TCP port 683.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>ics</category><category>dos</category><category>industrial-control-systems</category><category>critical-infrastructure</category><category>cve-2025-2399</category></item><item><title>Denial of Service Vulnerability in Mitsubishi Electric FA Products</title><link>https://feed.craftedsignal.io/briefs/2026-08-mitsubishi-fa-dos/</link><pubDate>Thu, 27 Aug 2026 16:05:55 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-mitsubishi-fa-dos/</guid><description>A vulnerability in the Ethernet function of multiple Mitsubishi Electric factory automation products allows remote attackers to trigger a denial-of-service condition via specially crafted UDP packets.</description><content:encoded><![CDATA[<p>Mitsubishi Electric has disclosed a high-severity vulnerability (CVE-2025-3511) affecting a wide array of Factory Automation (FA) products, including CC-Link IE TSN modules, MELSEC iQ-R series, and MELSEC iQ-F series controllers. The issue stems from Improper Validation of Specified Quantity in Input (CWE-1284) within the devices' Ethernet communication stack. By sending a specially crafted UDP packet to an affected device, a remote, unauthenticated attacker can induce a denial-of-service (DoS) condition, communication timeouts, or significant latency. Depending on the specific product, recovery requires a system reset or the resumption of valid UDP traffic. Given the deployment of these industrial control components within the critical manufacturing sector, this vulnerability poses a risk to operational availability and process continuity. Defenders should identify vulnerable assets within their OT networks and apply vendor-supplied firmware updates where available.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability impacts industrial control system infrastructure globally within the critical manufacturing sector. Successful exploitation results in a loss of network communication for critical I/O modules, CPUs, and interface modules. In many cases, a hardware reset is required to restore normal operations, which could lead to unplanned downtime and disruption of manufacturing processes.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all affected Mitsubishi Electric FA hardware using the provided product list and ensure internal inventory reflects the specified vulnerable firmware versions.</li>
<li>Implement network segmentation to isolate industrial Ethernet traffic, restricting access to these devices from untrusted network segments.</li>
<li>Monitor for anomalous UDP traffic patterns originating from unauthorized sources directed toward industrial Ethernet interfaces.</li>
<li>Prioritize firmware updates as provided by Mitsubishi Electric to address CVE-2025-3511 across the entire affected product line.</li>
</ul>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category><category>industrial-control-systems</category><category>denial-of-service</category><category>cve-2025-3511</category></item></channel></rss>