Home

Description

Expected Behavior Violation vulnerability in Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP all versions allows a remote attacker to cause a denial-of-service (DoS) condition in the affected product by continuously sending a large number of communication packets to the Ethernet port of the product in a short period of time, increasing the processing load of the product, preventing the internal anomaly-detection processing from being performed, and causing the communication function to stop.

PUBLISHED Reserved 2026-05-18 | Published 2026-06-19 | Updated 2026-06-19 | Assigner Mitsubishi




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-440 Expected Behavior Violation

Product status

Default status
unaffected

All versions
affected

References

www.mitsubishielectric.com/...nerability/pdf/2026-003_en.pdf vendor-advisory

jvn.jp/vu/JVNVU97140216/ government-resource

www.cisa.gov/news-events/ics-advisories/icsa-26-169-06 government-resource

cve.org (CVE-2026-8806)

nvd.nist.gov (CVE-2026-8806)

Download JSON