CISA Flags Denial-of-Service Vulnerability in Mitsubishi Electric CNC Systems
CISA has issued an advisory detailing a critical denial-of-service vulnerability affecting multiple Mitsubishi Electric CNC series products, urging immediate patching.

The Cybersecurity and Infrastructure Security Agency (CISA) has alerted organizations to a significant vulnerability impacting various Mitsubishi Electric CNC series products. Identified as CVE-2025-2399, the flaw stems from an improper validation of input, allowing remote attackers to trigger an out-of-bounds read.
Successful exploitation of this vulnerability could lead to a denial-of-service (DoS) condition. Attackers can achieve this by sending specially crafted packets to TCP port 683 on the affected devices. This could disrupt the normal operation of critical manufacturing equipment, potentially leading to significant downtime and operational losses.
The vulnerability affects a wide range of Mitsubishi Electric CNC models, including the M800VW, M800VS, M80V, M80VW, M800W, M800S, M80, M80W, E80, C80, M750VW, M730VW, M720VW, M750VS, M730VS, M720VS, M70V, and E70 series. The affected versions vary by model, ranging from "<=BB" and "<=FM" to "<=LJ" and "vers:all/*". The broad impact across numerous product lines underscores the widespread potential exposure within the critical manufacturing sector.
Mitsubishi Electric has acknowledged the vulnerability and provided updated versions for the affected products. Customers are advised to apply the fixed versions, such as "BC or later" for some models and "FN or later" for others, as specified in the advisory. For detailed instructions on applying these patches, users should consult their Mitsubishi Electric representative.
For organizations unable to immediately update their systems, Mitsubishi Electric offers several mitigation strategies. These include implementing firewalls or VPNs to prevent unauthorized external access, restricting the product's use to within a local area network (LAN) and blocking access from untrusted networks, and utilizing IP filter functions where available. Physical access restrictions and the installation of anti-virus software on connected PCs are also recommended.
The CVSS v3 score for this vulnerability is rated at 5.9, classifying it as medium severity. While not reaching the critical threshold, the potential for denial-of-service in industrial control systems warrants significant attention due to the operational impact.
This advisory highlights the ongoing cybersecurity challenges within the industrial control systems (ICS) and operational technology (OT) landscape. Vulnerabilities in specialized manufacturing equipment can have far-reaching consequences, impacting production lines and critical infrastructure. The prompt release of this advisory by CISA and the provision of patches by Mitsubishi Electric are crucial steps in mitigating the risk.
Organizations utilizing Mitsubishi Electric CNC equipment are strongly encouraged to review the CISA advisory thoroughly, identify their specific affected models and versions, and implement the recommended patches or mitigations without delay to protect their operations from potential disruption.