VYPR
advisoryPublished Jul 30, 2026· 1 source

Mitsubishi Electric CC-Link IE TSN Protocol Vulnerable to Denial-of-Service Attacks

CISA has issued an advisory for Mitsubishi Electric's CC-Link IE TSN Communication Protocol, detailing a vulnerability that could allow network-based attackers to cause denial-of-service conditions.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released an advisory detailing a critical vulnerability within Mitsubishi Electric's CC-Link IE TSN Communication Protocol. This vulnerability, identified as CVE-2026-13584, poses a significant risk to industrial control systems that rely on this protocol for communication.

Successful exploitation of CVE-2026-13584 could permit an attacker with access to the same network segment to disrupt operations. By sending specially crafted packets under precise timing conditions, an attacker can interfere with communication data. This interference can lead to a denial-of-service (DoS) condition, causing the affected product to malfunction or cease its control functions.

The vulnerability impacts a wide array of Mitsubishi Electric products, including numerous MELSEC controllers, modules, and interface boards. Specifically, affected devices range from the MELSEC MX Controller MX-R and MX-F models to various Master/local modules like the RJ71GN11-T2 and interface boards such as the NZ81GN11-SX. The advisory lists a comprehensive set of affected hardware, emphasizing the broad potential impact across industrial environments.

Among the extensively affected product lines are multiple Mitsubishi Electric Motion modules, such as the RD78G series and FX5-SSC-G models, as well as various Block-type remote modules and converter modules. The advisory notes that all versions of these listed products are susceptible to this vulnerability, indicating a widespread issue that requires immediate attention from users and administrators.

While the advisory does not specify a patch or workaround, it highlights the critical nature of the vulnerability. Organizations utilizing Mitsubishi Electric's CC-Link IE TSN protocol are urged to review the advisory thoroughly and implement appropriate network segmentation and access controls to mitigate the risk of exploitation. Further guidance on remediation is expected from Mitsubishi Electric.

The nature of this vulnerability, allowing for DoS through crafted network packets, is a common concern in industrial control system (ICS) environments. Such attacks can lead to significant operational disruptions, potentially causing costly downtime and impacting critical infrastructure. The reliance on specific timing conditions for exploitation suggests a need for robust network monitoring and intrusion detection systems capable of identifying anomalous traffic patterns.

This advisory serves as a reminder of the ongoing security challenges facing the operational technology (OT) sector. As industrial systems become increasingly interconnected, vulnerabilities in communication protocols can have far-reaching consequences. Users of Mitsubishi Electric equipment are strongly advised to stay informed about potential updates and security recommendations from the vendor and CISA.

CISA has assigned this advisory a CVSS v3.1 base score of 7.5, categorizing it as High severity. The agency recommends that users review the CSAF (Cybersecurity Advisory Framework) summary for detailed technical information and mitigation strategies, although specific remediation steps are not yet publicly detailed.

Synthesized by Vypr AI