Mitsubishi Electric CNC Series (Update A)
A vulnerability (CWE-1285) exists in Mitsubishi Electric CNC Series (Update A) products, allowing a remote attacker to cause a denial-of-service by sending crafted packets to TCP port 683. This affects a wide range of CNC machines used in critical infrastructure sectors, particularly manufacturing. Mitigation strategies include vendor patches, firewall usage, VPNs, IP filtering, and restricting physical access to the affected devices. The vulnerability is being reported and republished by CISA to increase visibility.
A critical vulnerability (CWE-1285) has been identified in Mitsubishi Electric CNC Series (Update A) products. This vulnerability allows a remote attacker to cause a denial-of-service condition by sending specially crafted packets to TCP port 683. The affected products include:
- Mitsubishi Electric M800VW (BND-2051W000): <=BB
- Mitsubishi Electric M800VS (BND-2052W000): <=BB
- Mitsubishi Electric M80V (BND-2053W000): <=BB
- Mitsubishi Electric M80VW (BND-2054W000): <=BB
- Mitsubishi Electric M800W (BND-2005W000): <=FM
- Mitsubishi Electric M800S (BND-2006W000): <=FM
- Mitsubishi Electric M80 (BND-2007W000): <=FM
- Mitsubishi Electric M80W (BND-2008W000): <=FM
- Mitsubishi Electric E80 (BND-2009W000): <=FM
- Mitsubishi Electric C80 (BND-2036W000): vers:all/*
- Mitsubishi Electric M750VW (BND-1015W002): <=LJ
- Mitsubishi Electric M730VW (BND-1015W000): <=LJ
- Mitsubishi Electric M720VW (BND-1015W000): <=LJ
- Mitsubishi Electric M750VS (BND-1012W002): <=LJ
- Mitsubishi Electric M730VS (BND-1012W000): <=LJ
- Mitsubishi Electric M720VS (BND-1012W000): <=LJ
- Mitsubishi Electric M70V (BND-1018W000): <=LJ
- Mitsubishi Electric E70 (BND-1022W000): <=LJ
The vulnerability stems from improper validation of specified index, position, or offset in input. This allows an attacker to craft packets that cause a buffer overflow and subsequent denial-of-service. The affected products are used in critical infrastructure sectors, particularly manufacturing. CISA is republishing this advisory to increase awareness and encourage prompt action.
**Recommended Actions:**
- **Vendor Patches:** Apply the fixed version (BC or later) for M800VW, M800VS, M80V, and M80VW. Consult your Mitsubishi Electric representative for instructions.
- **Vendor Patches:** Apply the fixed version (FN or later) for M800W, M800S, M80, M80W, E80, and E70.
- **Vendor Patches:** Apply the fixed version (LK or later) for M750VW, M730VW, M720VW, M750VS, M730VS, M720VS, M70V, and E70.
- **General Mitigation:** Utilize firewalls, VPNs, IP filtering, and restrict physical access to the affected devices.
- **Network Segmentation:** Minimize network exposure for control system devices and isolate them from business networks.
- **Secure Remote Access:** Use more secure methods for remote access, recognizing that VPNs may have vulnerabilities.
CISA recommends organizations perform proper impact analysis and risk assessment prior to deploying defensive measures. Additional mitigation guidance and recommended practices are available on the ICS webpage at cisa.gov. This advisory is a verbatim republication of Mitsubishi Electric 2025-022.