CVE-2025-2399

MEDIUM

Mitsubishi Electric CNC - DoS

Title source: llm
STIX 2.1

Description

Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Series M800VW and M800VS, M80V Series M80V and M80VW, M800 Series M800W and M800S, M80 Series M80 and M80W, E80 Series E80, C80 Series C80, M700V Series M750VW, M720VW, 730VW, M720VS, M730VS, and M750VS, M70V Series M70V, E70 Series E70, and Software Tools NC Trainer2 and NC Trainer2 plus allows a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition by sending specially crafted packets to TCP port 683.

Scores

CVSS v3 5.9
EPSS 0.0008
EPSS Percentile 22.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1285
Status published
Products (20)
Mitsubishi Electric Corporation/Mitsubishi Electric CNC C80 Series C80 System Number BND-2036W000 all versions
Mitsubishi Electric Corporation/Mitsubishi Electric CNC E70 Series E70 System Number BND-1022W000 all versions
Mitsubishi Electric Corporation/Mitsubishi Electric CNC E80 Series E80 System Number BND-2009W000 versions FM and prior
Mitsubishi Electric Corporation/Mitsubishi Electric CNC M700V Series M720VS System Number BND-1012W000 all versions
Mitsubishi Electric Corporation/Mitsubishi Electric CNC M700V Series M720VW System Number BND-1015W000 all versions
Mitsubishi Electric Corporation/Mitsubishi Electric CNC M700V Series M730VS System Number BND-1012W000 all versions
Mitsubishi Electric Corporation/Mitsubishi Electric CNC M700V Series M730VW System Number BND-1015W000 all versions
Mitsubishi Electric Corporation/Mitsubishi Electric CNC M700V Series M750VS System Number BND-1012W002 all versions
Mitsubishi Electric Corporation/Mitsubishi Electric CNC M700V Series M750VW System Number BND-1015W002 all versions
Mitsubishi Electric Corporation/Mitsubishi Electric CNC M70V Series M70V System Number BND-1018W000 all versions
... and 10 more
Published Mar 10, 2026
Tracked Since Mar 10, 2026