Mitsubishi Electric OT Protocol Flaw Allows I/O Tampering from Adjacent Networks
A high-severity vulnerability (CVE-2026-13584) has been disclosed in the CC-Link IE TSN industrial communication protocol affecting multiple Mitsubishi Electric products, including MELSEC MX, MELSERVO, GOT3000, and industrial robots across all versions. Published by JVN on August 3, 2026, the flaw stems from incomplete message integrity verification, allowing an unauthenticated attacker with adjacent network access to inject crafted packets at precise timings. Successful exploitation can alter control input/output values, causing device malfunctions, control interference, or denial-of-service conditions across actuators, servos, robots, and HMIs. The vulnerability carries a CVSS v4.0 score of 7.1 and does not require internet-facing access, as attack vectors include compromised engineering workstations, maintenance ports, and open Ethernet ports within factory networks. Mitsubishi Electric PSIRT and CISA have issued advisories recommending physical access controls, network segmentation, firewall/ACL enforcement, and OT intrusion detection systems as mitigations.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in