Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series Q03UDVCPU, Q04UDVCPU, Q06UDVCPU, Q13UDVCPU, Q26UDVCPU, Q04UDPVCPU, Q06UDPVCPU, Q13UDPVCPU, and Q26UDPVCPU with the first 5 digits of serial No. "24082" to "27081" allows a remote attacker to cause an integer underflow by sending specially crafted packets to the affected product to stop Ethernet communication and the execution of control programs on the product, when the user authentication function is enabled. The user authentication function is enabled by default only when settings are configured by GX Works2, which complies with the Cybersecurity Law of the People's Republic of China, and is normally disabled.
History

Wed, 24 Sep 2025 06:00:00 +0000

Type Values Removed Values Added
References

Mon, 22 Sep 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Mitsubishi
Mitsubishi melsec-q Series
Mitsubishi Electric
Mitsubishi Electric melsec-q Series
Mitsubishielectric
Mitsubishielectric melsec-q Series
Vendors & Products Mitsubishi
Mitsubishi melsec-q Series
Mitsubishi Electric
Mitsubishi Electric melsec-q Series
Mitsubishielectric
Mitsubishielectric melsec-q Series

Fri, 19 Sep 2025 12:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 19 Sep 2025 09:45:00 +0000

Type Values Removed Values Added
Description Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series Q03UDVCPU, Q04UDVCPU, Q06UDVCPU, Q13UDVCPU, Q26UDVCPU, Q04UDPVCPU, Q06UDPVCPU, Q13UDPVCPU, and Q26UDPVCPU with the first 5 digits of serial No. "24082" to "27081" allows a remote attacker to cause an integer underflow by sending specially crafted packets to the affected product to stop Ethernet communication and the execution of control programs on the product, when the user authentication function is enabled. The user authentication function is enabled by default only when settings are configured by GX Works2, which complies with the Cybersecurity Law of the People's Republic of China, and is normally disabled.
Weaknesses CWE-130
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mitsubishi

Published: 2025-09-19T09:30:21.832Z

Updated: 2025-09-24T05:39:19.865Z

Reserved: 2025-08-04T08:24:14.341Z

Link: CVE-2025-8531

cve-icon Vulnrichment

Updated: 2025-09-19T11:46:07.016Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-19T10:15:36.807

Modified: 2025-09-24T06:15:47.653

Link: CVE-2025-8531

cve-icon Redhat

No data.