CRITICAL🇵🇱 Wersja polska

CVE-2025-3755

CVSS 9.1v3.1pub. 2025-05-29upd. 2026-04-15

Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules allows a remote unauthenticated attacker to read information in the product, to cause a Denial-of-Service (DoS) condition in MELSOFT connection, or to stop the operation of the CPU module (causing a DoS condtion on the CPU module), by sending specially crafted packets. The product is needed to reset for recovery.

🤖 AI Analysis
How it works

The vulnerability results from improper validation of index, position, or offset in input data (CWE-1285). An attacker sends specially crafted network packets to the CPU module without prior authentication. Depending on packet content, unauthorized information disclosure from the product, MELSOFT connection disruption or termination, or complete CPU module shutdown is possible. Restoring normal operation after module shutdown requires its restart.

Impact

An attacker can gain unauthorized access to information stored in the device and cause service interruption of the control system (DoS on MELSOFT connection or CPU module shutdown). Consequences may include disruption of industrial processes managed by vulnerable controllers.

Mitigation & patch

Apply patches available from the manufacturer according to the references (https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2025-003_en.pdf and https://www.cisa.gov/news-events/ics-advisories/icsa-25-153-03). Until patches are implemented, it is recommended to restrict network access to CPU modules using firewalls and industrial network segmentation, ensuring unauthorized hosts cannot send packets to vulnerable devices.

Who is affected

MELSEC iQ-F series CPU modules from Mitsubishi Electric Corporation — specific versions indicated in manufacturer references (Mitsubishi Electric PSIRT and CISA advisory ICSA-25-153-03).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References