← Back
OtherCISA Advisories·5 hours ago

Mitsubishi Electric CNC Series (Update A)

CVE-2025-2399 affects multiple Mitsubishi Electric CNC Series models across M800, M80, E80, C80, M750, M730, M720, M70, and E70 product lines, with a CVSS score of 5.9. A remote attacker can exploit improper input validation to send specially crafted packets to TCP port 683, triggering an out-of-bounds read that causes denial-of-service conditions. Mitsubishi Electric has released patched versions (BC, FN, or LK depending on product line), and interim mitigation includes network segmentation, firewall restrictions, IP filtering, and VPN deployment for organizations unable to immediately patch.

Read full article at CISA Advisories

Related Articles