Mitsubishi Electric Multiple FA Products (Update D)

Summary

Mitsubishi Electric has released an update concerning multiple FA products, specifically addressing a vulnerability (CVE-2025-3511) in their CC-Link IE TSN Remote I/O modules. Successful exploitation could lead to a denial-of-service condition, timeout errors, or communication delays.

IFF Assessment

FOE

This vulnerability, if exploited, can disrupt industrial operations by causing denial-of-service, which is detrimental to defenders.

Severity

7.5 High

Defender Context

This alert highlights a critical vulnerability in Mitsubishi Electric's industrial control systems, specifically the CC-Link IE TSN Remote I/O modules. Defenders must prioritize patching or implementing compensating controls for affected versions to prevent potential denial-of-service attacks that could disrupt manufacturing and operational technology environments. Monitoring network traffic for unusual UDP packet activity targeting these devices is also crucial.

Read Full Story →