| CVE ID | CVSS Score | Severity | Description |
|---|---|---|---|
| CVE-2025-3511 | 7.5 | high |
A denial-of-service (DoS) vulnerability due to Improper Validation of Specified Quantity in Input (CWE-1284) exists in the Ethernet function of multiple FA products. This vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted UDP packet if CC-Link IE TSN Remote I/O modules NZ2GN2S1-32D, NZ2GN2S1-32T, NZ2GN2S1-32TE, NZ2GN2S1-32DT, NZ2GN2S1-32DTE, NZ2GN2B1-32D, NZ2GN2B1-32T, NZ2GN2B1-32TE, NZ2GN2B1-32DT, NZ2GN2B1-32DTE, NZ2GNCF1-32D, NZ2GNCF1-32T, NZ2GNCE3-32D, NZ2GNCE3-32DT, NZ2GN12A4-16D, NZ2GN12A4-16DE, NZ2GN12A2-16T, NZ2GN12A2-16TE, NZ2GN12A42-16DT, NZ2GN12A42-16DTE, NZ2GN2S1-16D, NZ2GN2S1-16T, NZ2GN2S1-16TE, NZ2GN2B1-16D, NZ2GN2B1-16T, NZ2GN2B1-16TE, CC-Link IE TSN Analog-Digital Converter modules NZ2GN2S-60AD4, NZ2GN2B-60AD4, CC-Link IE TSN Digital-Analog Converter modules NZ2GN2S-60DA4 and NZ2GN2B-60DA4, CC-Link IE TSN FPGA modules NZ2GN2S-D41P01, NZ2GN2S-D41D01, NZ2GN2S-D41PD02, CC-Link IE TSN Remote Station Communication LSIs CP620 with GbE-PHY NZ2GACP620-300, and NZ2GACP620-60 does not receive a valid UDP packet within 3 seconds. This vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition on MELSEC iQ-R Series CC-Link IE TSN Master/Local Module RJ71GN11-T2, RJ71GN11-EIP, RJ71GN11-SX, MELSEC iQ-R Series Ethernet Interface Module RJ71EN71, CC-Link IE TSN master/local Station Communication LSIs CP610 NZ2GACP610-60, NZ2KT-NPETNG51, MELSEC iQ-F Series FX5 CC-Link IE TSN Master/Local Module FX5-CCLGN-MS, MELSEC iQ-R Series CPU module R04ENCPU (Network part), R08ENCPU (Network part), R16ENCPU (Network part), R32ENCPU (Network part), and R120ENCPU (Network part), by sending a specially crafted UDP packet. Or this vulnerability could allow a remote attacker to cause a communication delay in Simple CPU communication on MELSEC iQ-F Series FX5 Ethernet Module FX5-ENET and FX5-ENET/IP Ethernet Module FX5-ENET/IP, by sending a specially crafted UDP packet. A system reset of the product is required for recovery in all cases above. Additionally, this vulnerability could allow a remote attacker to cause a timeout error in CC-Link IEF Basic communication on MELSEC iQ-F Series FX5 Ethernet Module FX5-ENET and FX5-ENET/IP Ethernet Module FX5-ENET/IP, by sending a specially crafted UDP packet. Even if a timeout error occurs, communication will be restored once the affected product starts receiving valid UDP packets.
|