Executive brief
A vulnerability exists in the Mitsubishi Electric MELSEC iQ-F Series FX5-EIP module, which is used in industrial automation to manage EtherNet/IP communications. An attacker can crash the module by rapidly opening many network connections, leading to a denial-of-service condition. This can disrupt manufacturing processes, stop industrial operations, and require manual intervention to restore service.
Technical details
An integer overflow or wraparound vulnerability (CWE-190) exists in the EtherNet/IP function of the FX5-EIP module. The flaw is triggered when the device attempts to manage a rapid influx of TCP connections, leading to an inconsistency in the internal connection management process and subsequent improper memory access. A remote, unauthenticated attacker can exploit this over the network to cause a denial-of-service (DoS) condition. Mitsubishi Electric has released firmware version 1.001 to address this issue.
Affected products
- Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP 1.000 and prior
Timeline
- 2026-06-18: advisory: CISA and Mitsubishi Electric published advisories
- 2026-06-19: disclosed: JVN publication date