CVE-2026-13584

HIGHCVSS 7.1/10EPSS 0.11%

Last modified

CVE-2026-13584 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, Motion Control Board, Block-type remote module, Block-type remote module with safety functions, Analog-Digital converter module, Digital-Analog converter module, CC-Link IE TSN compatible coupler, FPGA module, Tension meter, AC Servo MELSERVO-J5, AC Servo MELSERVO-JET, Liner Track System MTR-S series Linear track control module, Inverter FR-A800/F800/E800 Series, Industrial Robot CR800-D series controller Network Base Card, CC-Link IE TSN expansion unit, CC-Link IE TSN-CC-Link IE Field Network bridge module, CC-Link IE TSN-AnyWireASLINK bridge module, Energy Measuring Unit CC-Link IE TSN Communication Unit, Industrial Computer MELIPC series, GOT3000 Series, CC-Link IE TSN Communication Unit, Motion Control Software, CC-Link IE TSN Communication Software for Windows, Analysis Support Software MELSOFT VIMA, Master/Local module Designated communication LSI DeviceKit, Master/Local module Designated communication LSI, Remote Station Communication LSI with GbE-PHY, CC-Link IE TSN Master/Local module Designated communication LSI SDK, and Remote station software development kit allows an attacker with access to a CC-Link IE TSN network to tamper with communication data (control input/output values) by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.. EPSS estimates a 0.11% chance of exploitation in the next 30 days.

Description

Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, Motion Control Board, Block-type remote module, Block-type remote module with safety functions, Analog-Digital converter module, Digital-Analog converter module, CC-Link IE TSN compatible coupler, FPGA module, Tension meter, AC Servo MELSERVO-J5, AC Servo MELSERVO-JET, Liner Track System MTR-S series Linear track control module, Inverter FR-A800/F800/E800 Series, Industrial Robot CR800-D series controller Network Base Card, CC-Link IE TSN expansion unit, CC-Link IE TSN-CC-Link IE Field Network bridge module, CC-Link IE TSN-AnyWireASLINK bridge module, Energy Measuring Unit CC-Link IE TSN Communication Unit, Industrial Computer MELIPC series, GOT3000 Series, CC-Link IE TSN Communication Unit, Motion Control Software, CC-Link IE TSN Communication Software for Windows, Analysis Support Software MELSOFT VIMA, Master/Local module Designated communication LSI DeviceKit, Master/Local module Designated communication LSI, Remote Station Communication LSI with GbE-PHY, CC-Link IE TSN Master/Local module Designated communication LSI SDK, and Remote station software development kit allows an attacker with access to a CC-Link IE TSN network to tamper with communication data (control input/output values) by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.

Metrics

CVSS 4.0
7.1/10

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

EPSS Probability
0.11%

1.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
Mitsubishi Electric CorporationMELSEC MX Controller MX-R model MXR300-16all versions
Mitsubishi Electric CorporationMELSEC MX Controller MX-R model MXR300-32all versions
Mitsubishi Electric CorporationMELSEC MX Controller MX-R model MXR300-64all versions
Mitsubishi Electric CorporationMELSEC MX Controller MX-R model MXR500-128all versions
Mitsubishi Electric CorporationMELSEC MX Controller MX-R model MXR500-256all versions
Mitsubishi Electric CorporationMELSEC MX Controller MX-F model MXF100-8-N32all versions
Mitsubishi Electric CorporationMELSEC MX Controller MX-F model MXF100-8-P32all versions
Mitsubishi Electric CorporationMELSEC MX Controller MX-F model MXF100-16-N32all versions
Mitsubishi Electric CorporationMELSEC MX Controller MX-F model MXF100-16-P32all versions
Mitsubishi Electric CorporationMaster/local module RJ71GN11-T2all versions
Mitsubishi Electric CorporationMaster/local module RJ71GN11-SXall versions
Mitsubishi Electric CorporationMaster/local module RJ71GN11-EIPall versions
Mitsubishi Electric CorporationMaster/local module FX5-CCLGN-MSall versions
Mitsubishi Electric CorporationCC-Link IE TSN interface board NZ81GN11-SXall versions
Mitsubishi Electric CorporationCC-Link IE TSN interface board NZ81GN11-T2all versions
Mitsubishi Electric CorporationMotion module RD78G4all versions
Mitsubishi Electric CorporationMotion module RD78G8all versions
Mitsubishi Electric CorporationMotion module RD78G16all versions
Mitsubishi Electric CorporationMotion module RD78G64all versions
Mitsubishi Electric CorporationMotion module RD78GHVall versions
Mitsubishi Electric CorporationMotion module RD78GHWall versions
Mitsubishi Electric CorporationMotion module FX5-40SSC-Gall versions
Mitsubishi Electric CorporationMotion module FX5-80SSC-Gall versions
Mitsubishi Electric CorporationMotion Control Board MR-EM441Gall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN2S1-32Dall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN2S1-32Tall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN2S1-32TEall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN2S1-32DTall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN2S1-32DTEall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN2B1-32Dall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN2B1-32Tall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN2B1-32TEall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN2B1-32DTall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN2B1-32DTEall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GNCF1-32Dall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GNCF1-32Tall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GNCE3-32Dall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GNCE3-32DTall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN12A4-16Dall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN12A4-16DEall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN12A2-16Tall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN12A2-16TEall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN12A42-16DTall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN12A42-16DTEall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN2S1-16Dall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN2S1-16Tall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN2S1-16TEall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN2B1-16Dall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN2B1-16Tall versions
Mitsubishi Electric CorporationBlock-type remote module NZ2GN2B1-16TEall versions

Showing 50 of 115 affected configurations. See the CNA advisory for the full list.

References

Timeline

Published
Last Modified
Status
Deferred

Frequently Asked Questions

What is CVE-2026-13584?
Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, Motion Control Board, Block-type remote module, Block-type remote module with safety functions, Analog-Digital converter module, Digital-Analog converter module, CC-Link IE TSN compatible coupler, FPGA module, Tension meter, AC Servo MELSERVO-J5, AC Servo MELSERVO-JET, Liner Track System MTR-S series Linear track control module, Inverter FR-A800/F800/E800 Series, Industrial Robot CR800-D series controller Network Base Card, CC-Link IE TSN expansion unit, CC-Link IE TSN-CC-Link IE Field Network bridge module, CC-Link IE TSN-AnyWireASLINK bridge module, Energy Measuring Unit CC-Link IE TSN Communication Unit, Industrial Computer MELIPC series, GOT3000 Series, CC-Link IE TSN Communication Unit, Motion Control Software, CC-Link IE TSN Communication Software for Windows, Analysis Support Software MELSOFT VIMA, Master/Local module Designated communication LSI DeviceKit, Master/Local module Designated communication LSI, Remote Station Communication LSI with GbE-PHY, CC-Link IE TSN Master/Local module Designated communication LSI SDK, and Remote station software development kit allows an attacker with access to a CC-Link IE TSN network to tamper with communication data (control input/output values) by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.
How severe is CVE-2026-13584?
CVE-2026-13584 has a CVSS score of 7.1/10 (HIGH severity). The EPSS model estimates a 0.11% probability of exploitation in the next 30 days.
How do I fix CVE-2026-13584?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-13584?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST