CVE-2026-13584
Deferred Deferred - Pending Action

Improper Message Integrity in Mitsubishi Electric CC-Link IE TSN Products

Vulnerability report for CVE-2026-13584, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-30

Last updated on: 2026-08-04

Assigner: Mitsubishi Electric Corporation

Description

Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, Motion Control Board, Block-type remote module, Block-type remote module with safety functions, Analog-Digital converter module, Digital-Analog converter module, CC-Link IE TSN compatible coupler, FPGA module, Tension meter, AC Servo MELSERVO-J5, AC Servo MELSERVO-JET, Liner Track System MTR-S series Linear track control module, Inverter FR-A800/F800/E800 Series, Industrial Robot CR800-D series controller Network Base Card, CC-Link IE TSN expansion unit, CC-Link IE TSN-CC-Link IE Field Network bridge module, CC-Link IE TSN-AnyWireASLINK bridge module, Energy Measuring Unit CC-Link IE TSN Communication Unit, Industrial Computer MELIPC series, GOT3000 Series, CC-Link IE TSN Communication Unit, Motion Control Software, CC-Link IE TSN Communication Software for Windows, Analysis Support Software MELSOFT VIMA, Master/Local module Designated communication LSI DeviceKit, Master/Local module Designated communication LSI, Remote Station Communication LSI with GbE-PHY, CC-Link IE TSN Master/Local module Designated communication LSI SDK, and Remote station software development kit allows an attacker with access to a CC-Link IE TSN network to tamper with communication data (control input/output values) by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-30
Last Modified
2026-08-04
Generated
2026-08-19
AI Q&A
2026-07-30
EPSS Evaluated
2026-08-18
NVD
EUVD

Affected Vendors & Products

Showing 68 associated CPEs
Vendor Product Version / Range
mitsubishi_electric melsec_mx_controller *-*-*-*-*-*-*-*-*-*
mitsubishi_electric melsec_mx_controller_mx_r *-*-*-*-*-*-*-*-*-*
mitsubishi_electric melsec_mx_controller_mx_f *-*-*-*-*-*-*-*-*-*
mitsubishi_electric master_local_module *-*-*-*-*-*-*-*-*-*
mitsubishi_electric cc_link_ie_tsn_interface_board *-*-*-*-*-*-*-*-*-*
mitsubishi_electric motion_module *-*-*-*-*-*-*-*-*-*
mitsubishi_electric motion_control_board *-*-*-*-*-*-*-*-*-*
mitsubishi_electric block_type_remote_module *-*-*-*-*-*-*-*-*-*
mitsubishi_electric block_type_remote_module_with_safety_functions *-*-*-*-*-*-*-*-*-*
mitsubishi_electric analog_digital_converter_module *-*-*-*-*-*-*-*-*-*
mitsubishi_electric digital_analog_converter_module *-*-*-*-*-*-*-*-*-*
mitsubishi_electric cc_link_ie_tsn_compatible_coupler *-*-*-*-*-*-*-*-*-*
mitsubishi_electric fpga_module *-*-*-*-*-*-*-*-*-*
mitsubishi_electric tension_meter *-*-*-*-*-*-*-*-*-*
mitsubishi_electric ac_servo_melservo_j5 *-*-*-*-*-*-*-*-*-*
mitsubishi_electric ac_servo_melservo_jet *-*-*-*-*-*-*-*-*-*
mitsubishi_electric liner_track_system_mtr_s_series_linear_track_control_module *-*-*-*-*-*-*-*-*-*
mitsubishi_electric inverter_fr_a800_f800_e800_series *-*-*-*-*-*-*-*-*-*
mitsubishi_electric industrial_robot_cr800_d_series_controller_network_base_card *-*-*-*-*-*-*-*-*-*
mitsubishi_electric cc_link_ie_tsn_expansion_unit *-*-*-*-*-*-*-*-*-*
mitsubishi_electric cc_link_ie_tsn_cc_link_ie_field_network_bridge_module *-*-*-*-*-*-*-*-*-*
mitsubishi_electric cc_link_ie_tsn_anywireaslink_bridge_module *-*-*-*-*-*-*-*-*-*
mitsubishi_electric energy_measuring_unit_cc_link_ie_tsn_communication_unit *-*-*-*-*-*-*-*-*-*
mitsubishi_electric industrial_computer_melipc_series *-*-*-*-*-*-*-*-*-*
mitsubishi_electric got3000_series *-*-*-*-*-*-*-*-*-*
mitsubishi_electric cc_link_ie_tsn_communication_unit *-*-*-*-*-*-*-*-*-*
mitsubishi_electric motion_control_software *-*-*-*-*-*-*-*-*-*
mitsubishi_electric cc_link_ie_tsn_communication_software_for_windows *-*-*-*-*-*-*-*-*-*
mitsubishi_electric analysis_support_software_melsoft_vima *-*-*-*-*-*-*-*-*-*
mitsubishi_electric master_local_module_designated_communication_lsi_devicekit *-*-*-*-*-*-*-*-*-*
mitsubishi_electric master_local_module_designated_communication_lsi *-*-*-*-*-*-*-*-*-*
mitsubishi_electric remote_station_communication_lsi_with_gbe_phy *-*-*-*-*-*-*-*-*-*
mitsubishi_electric cc_link_ie_tsn_master_local_module_designated_communication_lsi_sdk *-*-*-*-*-*-*-*-*-*
mitsubishi_electric remote_station_software_development_kit *-*-*-*-*-*-*-*-*-*
mitsubishi electric melsec_mx_controller
mitsubishi electric melsec_mx_controller_mx_r
mitsubishi electric melsec_mx_controller_mx_f
mitsubishi electric master_local_module
mitsubishi electric cc_link_ie_tsn_interface_board
mitsubishi electric motion_module
mitsubishi electric motion_control_board
mitsubishi electric block_type_remote_module
mitsubishi electric block_type_remote_module_with_safety_functions
mitsubishi electric analog_digital_converter_module
mitsubishi electric digital_analog_converter_module
mitsubishi electric cc_link_ie_tsn_compatible_coupler
mitsubishi electric fpga_module
mitsubishi electric tension_meter
mitsubishi electric ac_servo_melservo_j5
mitsubishi electric ac_servo_melservo_jet
mitsubishi electric liner_track_system_mtr_s_series_linear_track_control_module
mitsubishi electric inverter_fr_a800_f800_e800_series
mitsubishi electric industrial_robot_cr800_d_series_controller_network_base_card
mitsubishi electric cc_link_ie_tsn_expansion_unit
mitsubishi electric cc_link_ie_tsn_cc_link_ie_field_network_bridge_module
mitsubishi electric cc_link_ie_tsn_anywireaslink_bridge_module
mitsubishi electric energy_measuring_unit_cc_link_ie_tsn_communication_unit
mitsubishi electric industrial_computer_melipc_series
mitsubishi electric got3000_series
mitsubishi electric cc_link_ie_tsn_communication_unit
mitsubishi electric motion_control_software
mitsubishi electric cc_link_ie_tsn_communication_software_for_windows
mitsubishi electric analysis_support_software_melsoft_vima
mitsubishi electric master_local_module_designated_communication_lsi_devicekit
mitsubishi electric master_local_module_designated_communication_lsi
mitsubishi electric remote_station_communication_lsi_with_gbe_phy
mitsubishi electric cc_link_ie_tsn_master_local_module_designated_communication_lsi_sdk
mitsubishi electric remote_station_software_development_kit

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-924 The product establishes a communication channel with an endpoint and receives a message from that endpoint, but it does not sufficiently ensure that the message was not modified during transmission.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper enforcement of message integrity during transmission in Mitsubishi Electric's CC-Link IE TSN communication protocol. An attacker with network access can send specially crafted packets at specific times to tamper with communication data, potentially altering control input or output values. This could disrupt control functions or cause incorrect operation, leading to a denial-of-service condition.

Detection Guidance

Detection requires monitoring CC-Link IE TSN network traffic for irregular packets or tampered data. Use network analyzers like Wireshark to inspect traffic for malformed packets or unexpected control value changes. Check for unauthorized devices on the network and verify message integrity checks are enabled.

Impact Analysis

This vulnerability could allow an attacker to interfere with industrial control systems, causing equipment malfunctions, incorrect operations, or complete shutdowns. It may disrupt manufacturing processes, automation systems, or critical infrastructure relying on affected Mitsubishi Electric devices.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling unauthorized tampering with control data in industrial systems. Tampering risks data integrity breaches, which are critical under GDPR's accuracy principle and HIPAA's integrity requirements. A DoS condition may also disrupt operations, potentially violating availability requirements in both regulations.

Mitigation Strategies
  • Restrict physical access to the network and affected products to prevent unauthorized access.
  • Isolate devices within a trusted network separated from untrusted networks using firewalls.
  • Configure credentials and access privileges for network devices to limit exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13584. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart