CVE-2026-13584
Last modified
CVE-2026-13584 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, Motion Control Board, Block-type remote module, Block-type remote module with safety functions, Analog-Digital converter module, Digital-Analog converter module, CC-Link IE TSN compatible coupler, FPGA module, Tension meter, AC Servo MELSERVO-J5, AC Servo MELSERVO-JET, Liner Track System MTR-S series Linear track control module, Inverter FR-A800/F800/E800 Series, Industrial Robot CR800-D series controller Network Base Card, CC-Link IE TSN expansion unit, CC-Link IE TSN-CC-Link IE Field Network bridge module, CC-Link IE TSN-AnyWireASLINK bridge module, Energy Measuring Unit CC-Link IE TSN Communication Unit, Industrial Computer MELIPC series, GOT3000 Series, CC-Link IE TSN Communication Unit, Motion Control Software, CC-Link IE TSN Communication Software for Windows, Analysis Support Software MELSOFT VIMA, Master/Local module Designated communication LSI DeviceKit, Master/Local module Designated communication LSI, Remote Station Communication LSI with GbE-PHY, CC-Link IE TSN Master/Local module Designated communication LSI SDK, and Remote station software development kit allows an attacker with access to a CC-Link IE TSN network to tamper with communication data (control input/output values) by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.. EPSS estimates a 0.11% chance of exploitation in the next 30 days.
Description
Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, Motion Control Board, Block-type remote module, Block-type remote module with safety functions, Analog-Digital converter module, Digital-Analog converter module, CC-Link IE TSN compatible coupler, FPGA module, Tension meter, AC Servo MELSERVO-J5, AC Servo MELSERVO-JET, Liner Track System MTR-S series Linear track control module, Inverter FR-A800/F800/E800 Series, Industrial Robot CR800-D series controller Network Base Card, CC-Link IE TSN expansion unit, CC-Link IE TSN-CC-Link IE Field Network bridge module, CC-Link IE TSN-AnyWireASLINK bridge module, Energy Measuring Unit CC-Link IE TSN Communication Unit, Industrial Computer MELIPC series, GOT3000 Series, CC-Link IE TSN Communication Unit, Motion Control Software, CC-Link IE TSN Communication Software for Windows, Analysis Support Software MELSOFT VIMA, Master/Local module Designated communication LSI DeviceKit, Master/Local module Designated communication LSI, Remote Station Communication LSI with GbE-PHY, CC-Link IE TSN Master/Local module Designated communication LSI SDK, and Remote station software development kit allows an attacker with access to a CC-Link IE TSN network to tamper with communication data (control input/output values) by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.
Metrics
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Mitsubishi Electric Corporation | MELSEC MX Controller MX-R model MXR300-16 | all versions |
| Mitsubishi Electric Corporation | MELSEC MX Controller MX-R model MXR300-32 | all versions |
| Mitsubishi Electric Corporation | MELSEC MX Controller MX-R model MXR300-64 | all versions |
| Mitsubishi Electric Corporation | MELSEC MX Controller MX-R model MXR500-128 | all versions |
| Mitsubishi Electric Corporation | MELSEC MX Controller MX-R model MXR500-256 | all versions |
| Mitsubishi Electric Corporation | MELSEC MX Controller MX-F model MXF100-8-N32 | all versions |
| Mitsubishi Electric Corporation | MELSEC MX Controller MX-F model MXF100-8-P32 | all versions |
| Mitsubishi Electric Corporation | MELSEC MX Controller MX-F model MXF100-16-N32 | all versions |
| Mitsubishi Electric Corporation | MELSEC MX Controller MX-F model MXF100-16-P32 | all versions |
| Mitsubishi Electric Corporation | Master/local module RJ71GN11-T2 | all versions |
| Mitsubishi Electric Corporation | Master/local module RJ71GN11-SX | all versions |
| Mitsubishi Electric Corporation | Master/local module RJ71GN11-EIP | all versions |
| Mitsubishi Electric Corporation | Master/local module FX5-CCLGN-MS | all versions |
| Mitsubishi Electric Corporation | CC-Link IE TSN interface board NZ81GN11-SX | all versions |
| Mitsubishi Electric Corporation | CC-Link IE TSN interface board NZ81GN11-T2 | all versions |
| Mitsubishi Electric Corporation | Motion module RD78G4 | all versions |
| Mitsubishi Electric Corporation | Motion module RD78G8 | all versions |
| Mitsubishi Electric Corporation | Motion module RD78G16 | all versions |
| Mitsubishi Electric Corporation | Motion module RD78G64 | all versions |
| Mitsubishi Electric Corporation | Motion module RD78GHV | all versions |
| Mitsubishi Electric Corporation | Motion module RD78GHW | all versions |
| Mitsubishi Electric Corporation | Motion module FX5-40SSC-G | all versions |
| Mitsubishi Electric Corporation | Motion module FX5-80SSC-G | all versions |
| Mitsubishi Electric Corporation | Motion Control Board MR-EM441G | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN2S1-32D | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN2S1-32T | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN2S1-32TE | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN2S1-32DT | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN2S1-32DTE | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN2B1-32D | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN2B1-32T | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN2B1-32TE | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN2B1-32DT | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN2B1-32DTE | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GNCF1-32D | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GNCF1-32T | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GNCE3-32D | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GNCE3-32DT | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN12A4-16D | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN12A4-16DE | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN12A2-16T | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN12A2-16TE | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN12A42-16DT | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN12A42-16DTE | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN2S1-16D | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN2S1-16T | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN2S1-16TE | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN2B1-16D | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN2B1-16T | all versions |
| Mitsubishi Electric Corporation | Block-type remote module NZ2GN2B1-16TE | all versions |
Showing 50 of 115 affected configurations. See the CNA advisory for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-13584?
How severe is CVE-2026-13584?
How do I fix CVE-2026-13584?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-13579A weakness has been identified in itsourcecode Hospital Mana…6.3
- CVE-2026-1358Airleader Master versions 6.381 and prior allow for file upl…9.8
- CVE-2026-13580A security vulnerability has been detected in Edimax EW-7478…8.8
- CVE-2026-13581A vulnerability was detected in Edimax EW-7478APC 1.04. This…6.3
- CVE-2026-13582A flaw has been found in Edimax EW-7478APC 1.04. This issue …8.8
- CVE-2026-13583A vulnerability has been found in Edimax EW-7478APC 1.04. Im…8.8
- CVE-2026-13585Allocation of Resources Without Limits and Throttling and Se…8.2
- CVE-2026-13586In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-d…5.3
- CVE-2026-13587A vulnerability was found in seladb PcapPlusPlus 25.05. The …3.7
- CVE-2026-13588A vulnerability was determined in seladb PcapPlusPlus 25.05.…5.6
- CVE-2026-13589A vulnerability was identified in seladb PcapPlusPlus 25.05.…5.6
- CVE-2026-1359The Genolve – AI image AI video generation plugin for WordPr…8.8
Are you affected by CVE-2026-13584?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
