CVE-2025-5514
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-08-25
Last updated on: 2025-08-25
Assigner: Mitsubishi Electric Corporation
Description
Description
Improper Handling of Length Parameter Inconsistency vulnerability in web server function on Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to delay the processing of the web server function and prevent legitimate users from utilizing the web server function, by sending a specially crafted HTTP request.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mitsubishi | electric_melsec_iq-f | fx5u |
| mitsubishi | electric_melsec_iq-f | fx5uc |
| mitsubishi | electric_melsec_iq-f | 1.060 |
| mitsubishi | electric_melsec_iq-f | fx5s |
| mitsubishi | electric_melsec_iq-f | fx5uj |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-130 | The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data. |