CVE-2025-2399

MEDIUMCVSS 5.9/10EPSS 0.61%

Last modified

CVE-2025-2399 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Series M800VW and M800VS, M80V Series M80V and M80VW, M800 Series M800W and M800S, M80 Series M80 and M80W, E80 Series E80, C80 Series C80, M700V Series M750VW, M720VW, 730VW, M720VS, M730VS, and M750VS, M70V Series M70V, E70 Series E70, and Software Tools NC Trainer2 and NC Trainer2 plus allows a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition by sending specially crafted packets to TCP port 683.. EPSS estimates a 0.61% chance of exploitation in the next 30 days.

Description

Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Series M800VW and M800VS, M80V Series M80V and M80VW, M800 Series M800W and M800S, M80 Series M80 and M80W, E80 Series E80, C80 Series C80, M700V Series M750VW, M720VW, 730VW, M720VS, M730VS, and M750VS, M70V Series M70V, E70 Series E70, and Software Tools NC Trainer2 and NC Trainer2 plus allows a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition by sending specially crafted packets to TCP port 683.

Metrics

CVSS 3.1
5.9/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
0.61%

44.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
Mitsubishi Electric CorporationMitsubishi Electric CNC M800V Series M800VWSystem Number BND-2051W000 versions BB and prior
Mitsubishi Electric CorporationMitsubishi Electric CNC M800V Series M800VSSystem Number BND-2052W000 versions BB and prior
Mitsubishi Electric CorporationMitsubishi Electric CNC M80V Series M80VSystem Number BND-2053W000 versions BB and prior
Mitsubishi Electric CorporationMitsubishi Electric CNC M80V Series M80VWSystem Number BND-2054W000 versions BB and prior
Mitsubishi Electric CorporationMitsubishi Electric CNC M800 Series M800WSystem Number BND-2005W000 versions FM and prior
Mitsubishi Electric CorporationMitsubishi Electric CNC M800 Series M800SSystem Number BND-2006W000 versions FM and prior
Mitsubishi Electric CorporationMitsubishi Electric CNC M80 Series M80System Number BND-2007W000 versions FM and prior
Mitsubishi Electric CorporationMitsubishi Electric CNC M80 Series M80WSystem Number BND-2008W000 versions FM and prior
Mitsubishi Electric CorporationMitsubishi Electric CNC E80 Series E80System Number BND-2009W000 versions FM and prior
Mitsubishi Electric CorporationMitsubishi Electric CNC C80 Series C80System Number BND-2036W000 all versions
Mitsubishi Electric CorporationMitsubishi Electric CNC M700V Series M750VWSystem Number BND-1015W002 all versions
Mitsubishi Electric CorporationMitsubishi Electric CNC M700V Series M720VWSystem Number BND-1015W000 all versions
Mitsubishi Electric CorporationMitsubishi Electric CNC M700V Series M730VWSystem Number BND-1015W000 all versions
Mitsubishi Electric CorporationMitsubishi Electric CNC M700V Series M720VSSystem Number BND-1012W000 all versions
Mitsubishi Electric CorporationMitsubishi Electric CNC M700V Series M730VSSystem Number BND-1012W000 all versions
Mitsubishi Electric CorporationMitsubishi Electric CNC M700V Series M750VSSystem Number BND-1012W002 all versions
Mitsubishi Electric CorporationMitsubishi Electric CNC M70V Series M70VSystem Number BND-1018W000 all versions
Mitsubishi Electric CorporationMitsubishi Electric CNC E70 Series E70System Number BND-1022W000 all versions
Mitsubishi Electric CorporationMitsubishi Electric CNC Software Tools NC Trainer2System Number BND-1802W000 all versions
Mitsubishi Electric CorporationMitsubishi Electric CNC Software Tools NC Trainer2 plusSystem Number BND-1803W000 all versions

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Frequently Asked Questions

What is CVE-2025-2399?
Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Series M800VW and M800VS, M80V Series M80V and M80VW, M800 Series M800W and M800S, M80 Series M80 and M80W, E80 Series E80, C80 Series C80, M700V Series M750VW, M720VW, 730VW, M720VS, M730VS, and M750VS, M70V Series M70V, E70 Series E70, and Software Tools NC Trainer2 and NC Trainer2 plus allows a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition by sending specially crafted packets to TCP port 683.
How severe is CVE-2025-2399?
CVE-2025-2399 has a CVSS score of 5.9/10 (MEDIUM severity). The EPSS model estimates a 0.61% probability of exploitation in the next 30 days.
How do I fix CVE-2025-2399?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2025

Are you affected by CVE-2025-2399?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST