PT-2026-50828 · Mitsubishi · Fx5-Eip
CVE-2026-8805
·
Published
2026-06-19
·
Updated
2026-06-22
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP module versions 1.000 and prior
Description
An integer overflow or wraparound in the EtherNet/IP function allows a remote attacker to cause a denial-of-service (DoS) condition. By rapidly establishing a large number of TCP connections, an attacker can create an inconsistency in the internal connection management process, triggering improper memory access. This can lead to conditions requiring full system resets, posing operational risks in industrial networks lacking proper traffic controls.
Recommendations
Update the FX5-EIP module to a version later than 1.000.
Fix
DoS
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fx5-Eip