CVE-2025-8531
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-19

Last updated on: 2025-09-24

Assigner: Mitsubishi Electric Corporation

Description
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series Q03UDVCPU, Q04UDVCPU, Q06UDVCPU, Q13UDVCPU, Q26UDVCPU, Q04UDPVCPU, Q06UDPVCPU, Q13UDPVCPU, and Q26UDPVCPU with the first 5 digits of serial No. "24082" to "27081" allows a remote attacker to cause an integer underflow by sending specially crafted packets to the affected product to stop Ethernet communication and the execution of control programs on the product, when the user authentication function is enabled. The user authentication function is enabled by default only when settings are configured by GX Works2, which complies with the Cybersecurity Law of the People's Republic of China, and is normally disabled.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-19
Last Modified
2025-09-24
Generated
2026-05-07
AI Q&A
2025-09-19
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 10 associated CPEs
Vendor Product Version / Range
mitsubishi electric_melsec-q_series Q06UDPVCPU
mitsubishi electric_melsec-q_series Q03UDVCPU
mitsubishi electric_melsec-q_series Q26UDPVCPU
mitsubishi electric_melsec-q_series Q13UDPVCPU
mitsubishi electric_melsec-q_series Q06UDVCPU
mitsubishi electric_melsec-q_series Q04UDPVCPU
mitsubishi electric_melsec-q_series 0
mitsubishi electric_melsec-q_series Q04UDVCPU
mitsubishi electric_melsec-q_series Q13UDVCPU
mitsubishi electric_melsec-q_series Q26UDVCPU
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-130 The product parses a formatted message or structure, but it does not handle or incorrectly handles a length field that is inconsistent with the actual length of the associated data.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability is an improper handling of length parameter inconsistency in certain Mitsubishi Electric MELSEC-Q Series CPU models. A remote attacker can send specially crafted packets to cause an integer underflow, which stops Ethernet communication and halts the execution of control programs on the affected device when the user authentication function is enabled.


How can this vulnerability impact me? :

The vulnerability can cause denial of service by stopping Ethernet communication and halting control program execution on the affected Mitsubishi Electric devices, potentially disrupting industrial or automation processes relying on these devices.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart