PT-2026-50828 · Mitsubishi · Fx5-Eip

CVE-2026-8805

·

Published

2026-06-19

·

Updated

2026-06-22

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP module versions 1.000 and prior
Description An integer overflow or wraparound in the EtherNet/IP function allows a remote attacker to cause a denial-of-service (DoS) condition. By rapidly establishing a large number of TCP connections, an attacker can create an inconsistency in the internal connection management process, triggering improper memory access. This can lead to conditions requiring full system resets, posing operational risks in industrial networks lacking proper traffic controls.
Recommendations Update the FX5-EIP module to a version later than 1.000.

Fix

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8805

Affected Products

Fx5-Eip