Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.9

Mitsubishi Electric CNC Machines: Denial of Service via Malicious Network Traffic

CVE-2025-2399
Summary

Attackers can send malicious network packets to Mitsubishi Electric CNC machines, causing them to crash and become unresponsive. This could disrupt production and operations. Mitsubishi Electric has released patches to fix the issue, which can be downloaded from their website.

Original title
Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Series M800VW and M800VS, M80V Series M80V and M80VW, M800 Series M800W and M800S...
Original description
Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Series M800VW and M800VS, M80V Series M80V and M80VW, M800 Series M800W and M800S, M80 Series M80 and M80W, E80 Series E80, C80 Series C80, M700V Series M750VW, M720VW, 730VW, M720VS, M730VS, and M750VS, M70V Series M70V, E70 Series E70, and Software Tools NC Trainer2 and NC Trainer2 plus allows a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition by sending specially crafted packets to TCP port 683.
nvd CVSS3.1 5.9
Vulnerability type
CWE-1285
Published: 10 Mar 2026 · Updated: 13 Mar 2026 · First seen: 11 Mar 2026