Vulnerability in Mitsubishi Electric MELSEC MX Controllers and Related Products
CVE-2026-13584

7.1HIGH

What is CVE-2026-13584?

An improper enforcement of message integrity during transmission vulnerability exists within various Mitsubishi Electric MELSEC MX Controllers and associated products. This flaw allows an attacker with access to a CC-Link IE TSN network to modify communication data, including control input/output values, by sending specially crafted packets. Under specific timing conditions, this manipulation can lead to interference with the control functions of the affected products, potentially causing them to operate incorrectly or resulting in a denial-of-service (DoS) state.

Affected Version(s)

AC Servo MELSERVO-J5 MR-J5-G all versions

AC Servo MELSERVO-J5 MR-J5-G-HS all versions

AC Servo MELSERVO-J5 MR-J5-G-LL all versions

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.