CVE Intelligence
Skip to main content
MEDIUM

CVE-2025-2399

CVE-2025-2399 — Denial of Service (DoS) Vulnerability in Mitsubishi Electric CNC Series

Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Series M800VW and M800VS, M80V Series M80V and M80VW, M800 Series M800W and M800S, M80 Series M80 and M80W, E80 Series E80, C80 Series C80, M700V Series M750VW, M720VW, 730VW, M720VS, M730VS, and M750VS, M70V Series M70V, E70 Series E70, and Software Tools NC Trainer2 and NC Trainer2 plus allows a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition by sending specially crafted packets to TCP port 683.

Published Updated Sources: cvelistV5, Mitsubishi

Triage

Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.

Exploitation

Unreported

no source claims exploitation

EPSS

1%

chance of exploitation in 30 days

Affects

mitsubishi electric

20 products listed

CVSS base

5.9

MEDIUM

CISA SSVC assessment

Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A stakeholder decision, not a severity score.

CISA

Exploitation

None

none · proof-of-concept · active

Automatable

No

can an attacker script all four kill-chain steps

Technical impact

Partial

partial · total control of the vulnerable component

Affected scope

The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.

Products (20)

mitsubishi electric cnc m800v series m800vwmitsubishi electric cnc m800v series m800vsmitsubishi electric cnc m80v series m80vmitsubishi electric cnc m80v series m80vwmitsubishi electric cnc m800 series m800wmitsubishi electric cnc m800 series m800smitsubishi electric cnc m80 series m80mitsubishi electric cnc m80 series m80wmitsubishi electric cnc e80 series e80mitsubishi electric cnc c80 series c80mitsubishi electric cnc m700v series m750vwmitsubishi electric cnc m700v series m720vwmitsubishi electric cnc m700v series m730vwmitsubishi electric cnc m700v series m720vsmitsubishi electric cnc m700v series m730vsmitsubishi electric cnc m700v series m750vsmitsubishi electric cnc m70v series m70vmitsubishi electric cnc e70 series e70mitsubishi electric cnc software tools nc trainer2mitsubishi electric cnc software tools nc trainer2 plus

Every base score collected

Sources score independently and disagree; each row says who scored it and under which version.

ScoreVersionSeverityExpl.ImpactSource
5.9CVSS 3.1MEDIUMcvelistV5

Weakness & attack patterns

  • CWE-1285

References

3 on the record

Elsewhere on this site

Not in any source we poll

Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.

  • No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
  • No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
  • No exploit packet captures, log samples, or incident case IDs supplied.