Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules allows a remote unauthenticated attacker to read information in the product, to cause a Denial-of-Service (DoS) condition in MELSOFT connection, or to stop the operation of the CPU module (causing a DoS condtion on the CPU module), by sending specially crafted packets. The product is needed to reset for recovery.
The vulnerability results from improper validation of index, position, or offset in input data (CWE-1285). An attacker sends specially crafted network packets to the CPU module without prior authentication. Depending on packet content, unauthorized information disclosure from the product, MELSOFT connection disruption or termination, or complete CPU module shutdown is possible. Restoring normal operation after module shutdown requires its restart.
An attacker can gain unauthorized access to information stored in the device and cause service interruption of the control system (DoS on MELSOFT connection or CPU module shutdown). Consequences may include disruption of industrial processes managed by vulnerable controllers.
Apply patches available from the manufacturer according to the references (https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-003_en.pdf and https://www.cisa.gov/news-events/ics-advisories/icsa-25-153-03). Until patches are implemented, it is recommended to restrict network access to CPU modules using firewalls and industrial network segmentation, ensuring unauthorized hosts cannot send packets to vulnerable devices.
MELSEC iQ-F series CPU modules from Mitsubishi Electric Corporation — specific versions indicated in manufacturer references (Mitsubishi Electric PSIRT and CISA advisory ICSA-25-153-03).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H