IM
IronMonkey Threat Research

CVE-2025-2399 MEDIUM

Published: 2026-03-10 | Last Modified: 2026-08-27 | Status: Awaiting Analysis

Description

Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Series M800VW and M800VS, M80V Series M80V and M80VW, M800 Series M800W and M800S, M80 Series M80 and M80W, E80 Series E80, C80 Series C80, and M700V Series M750VW, M720VW, 730VW, M720VS, M730VS, and M750VS, M70V Series M70V, E70 Series E70 allows a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition by sending specially crafted packets to TCP port 683.

Additional Descriptions (1)

Vulnerabilidad de validación incorrecta de índice, posición o desplazamiento especificados en la entrada en Mitsubishi Electric CNC Serie M800V M800VW y M800VS, Serie M80V M80V y M80VW, Serie M800 M800W y M800S, Serie M80 M80 y M80W, Serie E80 E80, Serie C80 C80, Serie M700V M750VW, M720VW, 730VW, M720VS, M730VS, y M750VS, Serie M70V M70V, Serie E70 E70, y Herramientas de software NC Trainer2 y NC Trainer2 plus permite a un atacante remoto causar una lectura fuera de límites, lo que resulta en una condición de denegación de servicio al enviar paquetes especialmente diseñados al puerto TCP 683.

CVSS Metrics

Base Score: 5.9 (MEDIUM)

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack VectorNETWORK
Attack ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Secondary

Exploitability Score: 2.2

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-1285
Notification
Message here