← Back
OtherCISA Advisories·5 hours ago

Mitsubishi Electric Multiple FA Products (Update D)

CVE-2025-3511 affects a wide range of Mitsubishi Electric factory automation products including CC-Link IE TSN modules, MELSEC controllers, and related networking equipment, allowing remote attackers to trigger denial-of-service conditions, timeouts, or communication delays by sending specially crafted UDP packets due to improper input validation. The vulnerability carries a CVSS score of 7.5 and impacts critical manufacturing infrastructure worldwide, with affected products across multiple device categories up to specific firmware versions. Mitsubishi Electric has released patched firmware versions and recommends network segmentation, firewalls, and VPN restrictions as immediate mitigations while updates are deployed.

Read full article at CISA Advisories

Related Articles