Mitsubishi Electric CC-Link IE TSN Communication Protocol
Summary
A vulnerability in Mitsubishi Electric's CC-Link IE TSN Communication Protocol allows an attacker on the same network segment to tamper with communication data by sending specially crafted packets under specific timing conditions. Successful exploitation could lead to a denial-of-service (DoS) condition or incorrect operation of the affected product.
IFF Assessment
This vulnerability allows attackers to disrupt industrial control systems, potentially causing operational failures and denial-of-service conditions.
Severity
The CVSS score is estimated to be 7.5 (High) due to the potential for network-based attack (Attack Vector: Network), the impact on integrity and availability (Impact: High), and the requirement for specific timing conditions, which is moderately complex but achievable.
Defender Context
This vulnerability impacts industrial control systems (ICS) and operational technology (OT) environments. Defenders should be aware of potential disruptions to critical infrastructure and ensure their networks are segmented to limit the attack surface for such protocol-specific exploits. Patching and monitoring for unusual network traffic related to the CC-Link IE TSN protocol are crucial mitigation steps.