Description
Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition on the product by sending specially crafted packets to TCP port 683, causing an emergency stop.
References (2)
Core 2
Core References
Various Sources vendor-advisory
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-007_en.pdf
Third Party Advisory government-resource
https://jvn.jp/vu/JVNVU92054409/index.html
Scores
CVSS v3
5.9
EPSS
0.0054
EPSS Percentile
41.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1284
Status
published
Products (20)
Mitsubishi Electric Corporation/Mitsubishi Electric CNC C80 Series C80
System Number BND-2036W000 versions BJ and prior
Mitsubishi Electric Corporation/Mitsubishi Electric CNC E70 Series E70
System Number BND-1022W000 versions LG and prior
Mitsubishi Electric Corporation/Mitsubishi Electric CNC E80 Series E80
System Number BND-2009W000 versions FH and prior
Mitsubishi Electric Corporation/Mitsubishi Electric CNC M700V Series M720VS
System Number BND-1012W000 versions LG and prior
Mitsubishi Electric Corporation/Mitsubishi Electric CNC M700V Series M720VW
System Number BND-1015W000 versions LG and prior
Mitsubishi Electric Corporation/Mitsubishi Electric CNC M700V Series M730VS
System Number BND-1012W000 versions LG and prior
Mitsubishi Electric Corporation/Mitsubishi Electric CNC M700V Series M730VW
System Number BND-1015W000 versions LG and prior
Mitsubishi Electric Corporation/Mitsubishi Electric CNC M700V Series M750VS
System Number BND-1012W002 versions LG and prior
Mitsubishi Electric Corporation/Mitsubishi Electric CNC M700V Series M750VW
System Number BND-1015W002 versions LG and prior
Mitsubishi Electric Corporation/Mitsubishi Electric CNC M70V Series M70V
System Number BND-1018W000 versions LG and prior
... and 10 more
Published
Oct 17, 2024
Tracked Since
Feb 18, 2026