CISA issued advisories for multiple vulnerabilities affecting Mitsubishi Electric MELSEC industrial automation products used in the Critical Manufacturing sector, including MELSEC PLC families, motion modules, CNC series, and MELSEC-F Series Ethernet modules. The most severe issue, CVE-2023-4699, is a missing authentication flaw (CWE-306) in Mitsubishi Electric proprietary protocol communications that can let a remote attacker send specially crafted packets to execute arbitrary commands; CISA rated it CVSS 10.0 and said the update expanded the list of affected products and revised mitigations and scoring.
A separate advisory covers CVE-2021-20613, an improper initialization flaw in MELSEC-F Series Ethernet modules including FX3U-ENET, FX3U-ENET-L, and FX3U-ENET-P502 running firmware 1.16 or earlier. That vulnerability can be exploited remotely with low attack complexity to trigger a denial-of-service condition in communications that requires a system reset, and Mitsubishi Electric released firmware 1.17 or later to fix it. Across both advisories, CISA and Mitsubishi Electric urged operators to isolate control networks, restrict access with firewalls or VPNs, apply IP filtering, keep devices on trusted LANs, and limit physical and remote exposure; neither advisory reported known public exploitation targeting the flaws.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
68 events from the most recent confirmed update back to the earliest known activity.
JVN published advisory JVNVU#93286687 covering multiple vulnerabilities in the Ethernet functions of Mitsubishi Electric MELSEC iQ-F Series EtherNet/IP units and Ethernet units. The disclosure represents a new coordinated vulnerability advisory for this product line not already reflected in the timeline.
Mitsubishi Electric published PSIRT advisory 2025-020 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2025-005, 2025-011, and earlier PSIRT notices.
Mitsubishi Electric published PSIRT advisory 2025-014 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2025-005, 2025-010, 2025-011, and 2025-020 notices.
Mitsubishi Electric published PSIRT advisory 2025-011 for a separate product vulnerability not currently captured in the timeline. The advisory represents a new vendor disclosure event distinct from the previously tracked 2021-011, CVE-2021-20613, and CVE-2023-4699 notices.
Mitsubishi Electric published PSIRT advisory 2025-005 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2025-011 and earlier PSIRT notices.
Mitsubishi Electric published PSIRT advisory 2025-003 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2025-005, 2025-010, 2025-011, 2025-014, and 2025-020 notices.
Mitsubishi Electric published PSIRT advisory 2025-010 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2025-005, 2025-011, and 2025-020 notices.
CISA updated advisory ICSA-23-306-03 to add additional affected Mitsubishi Electric products and mitigations, and to revise the CVSS scoring and vulnerability description for CVE-2023-4699.
Mitsubishi Electric published PSIRT advisory 2024-007 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2020-005, 2020-017, 2021-011, 2022-006, 2023-004, 2023-006, 2023-011, 2024-004, and 2025-011 notices.
CISA published Update E for advisory ICSA-22-356-03 covering vulnerabilities affecting Mitsubishi Electric MELSEC iQ-R Series, MELSEC iQ-L Series, and MELIPC Series products. The advisory represents a separate government disclosure/update event from the other Mitsubishi Electric CISA notices already tracked in the timeline.
Mitsubishi Electric published PSIRT advisory 2024-005 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2024-002, 2024-004, 2024-007, and other Mitsubishi Electric PSIRT notices.
Mitsubishi Electric published PSIRT advisory 2024-003 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2024-002, 2024-004, 2024-005, 2024-007, and 2024-009 notices.
Mitsubishi Electric published PSIRT advisory 2024-004 for a separate product vulnerability not currently represented in the timeline. The advisory marks a distinct vendor disclosure event apart from the previously tracked 2021-011, 2022-006, 2023-006, 2023-011, and 2025-011 notices.
Mitsubishi Electric published PSIRT advisory 2024-002 for a separate product vulnerability not currently represented in the timeline. This is a distinct vendor disclosure event from the already tracked 2024-004, 2024-007, and other Mitsubishi Electric PSIRT notices.
CISA published advisory ICSA-24-044-01 for CVE-2023-6815 affecting Mitsubishi Electric MELSEC iQ-R Series Safety CPU and SIL2 Process CPU products. The advisory said a remote authenticated non-administrator user could disclose lower-privileged user credentials via a specially crafted packet, and it included Mitsubishi Electric mitigations and compensating controls.
CISA published Update B for advisory ICSA-21-287-03 covering vulnerabilities affecting Mitsubishi Electric MELSEC iQ-R Series products. This represents a distinct government advisory update event for a product line and advisory not already captured in the timeline.
Mitsubishi Electric published PSIRT advisory 2023-024 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2023-series, 2024-series, and 2025-series PSIRT notices.
Mitsubishi Electric published PSIRT advisory 2023-022 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2023-series, 2024-series, and 2025-series PSIRT notices.
CISA published Update A for advisory ICSA-23-306-02 covering vulnerabilities affecting Mitsubishi Electric MELSEC iQ-F Series and MELSEC iQ-R Series CPU modules. The update represents a distinct government advisory event for a Mitsubishi Electric product line not yet captured in the timeline.
Mitsubishi Electric published PSIRT advisory 2023-021 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2023-series, 2024-series, and 2025-series PSIRT notices.
Mitsubishi Electric published PSIRT advisory 2024-009 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2024-002, 2024-004, 2024-005, and 2024-007 notices.
Mitsubishi Electric published PSIRT advisory 2023-018 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2023-004, 2023-006, 2023-010, 2023-011, 2023-014, and later PSIRT notices.
Mitsubishi Electric published PSIRT advisory 2023-015 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2023-014, 2023-018, 2023-019, 2023-021, 2023-022, and 2023-024 notices.
CISA initially published advisory ICSA-23-306-03 covering CVE-2023-4699, a critical missing authentication vulnerability in Mitsubishi Electric proprietary protocol communications that could allow remote attackers to execute arbitrary commands on affected FA and CNC products.
Mitsubishi Electric published PSIRT advisory 2023-014 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2023-006, 2023-011, 2024-004, and 2025-011 notices.
Mitsubishi Electric published PSIRT advisory 2023-013 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2023-004, 2023-006, 2023-009, 2023-010, 2023-011, 2023-014, and 2023-018 notices.
Mitsubishi Electric published vendor advisory 2023-006 for CVE-2023-4699, describing a missing authentication flaw in proprietary protocol communications affecting FA and CNC products. The advisory provided product impact details and vendor guidance ahead of or alongside broader government coordination.
Mitsubishi Electric published PSIRT advisory 2023-012 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2023-009, 2023-010, 2023-011, 2023-013, 2023-014, 2023-018, 2023-022, and 2023-024 notices.
Mitsubishi Electric published PSIRT advisory 2023-011 for a separate product vulnerability not currently represented in the timeline. The advisory is a distinct vendor disclosure event from the already tracked 2021-011, 2022-006, 2023-006, and 2025-011 notices.
Mitsubishi Electric published PSIRT advisory 2023-009 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2023-006, 2023-010, 2023-011, 2023-014, and 2023-018 notices.
Mitsubishi Electric published PSIRT advisory 2023-005 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2023-004, 2023-006, and other Mitsubishi Electric PSIRT notices.
Mitsubishi Electric published PSIRT advisory 2023-004 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2020-005, 2021-011, 2022-006, 2023-006, 2023-011, 2024-004, and 2025-011 notices.
Mitsubishi Electric published PSIRT advisory 2023-002 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2023-series, 2024-series, and 2025-series PSIRT notices.
Mitsubishi Electric published PSIRT advisory 2023-001 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the other tracked 2023-series, 2024-series, and 2025-series PSIRT notices.
CISA published advisory ICSA-23-017-02 covering vulnerabilities affecting Mitsubishi Electric MELSEC iQ-F and iQ-R Series products. The advisory represents a separate government disclosure event for different Mitsubishi Electric product lines than those already tracked in the timeline.
Mitsubishi Electric published PSIRT advisory 2023-019 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2023-018, 2023-021, 2023-022, 2023-024, and other Mitsubishi Electric PSIRT notices.
Mitsubishi Electric published PSIRT advisory 2023-010 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2023-004, 2023-006, 2023-011, and 2023-014 notices.
Mitsubishi Electric published PSIRT advisory 2023-007 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2023-006, 2023-009, 2023-010, 2023-011, 2023-012, 2023-013, 2023-014, 2023-018, 2023-022, and 2023-024 notices.
Mitsubishi Electric published PSIRT advisory 2022-018 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2022-001, 2022-006, 2022-009, 2022-016, and later PSIRT notices.
Mitsubishi Electric published PSIRT advisory 2022-016 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event apart from the already tracked 2022-006, 2023-006, 2024-004, and 2025-011 notices.
CISA published advisory ICSA-22-172-01 for CVE-2022-24946 affecting Mitsubishi Electric MELSEC iQ-R, Q, and L Series CPU modules and MELIPC Series CPU products. The advisory said remote exploitation could disrupt Ethernet communications and require a restart, while Mitsubishi Electric provided fixes for some product ranges and mitigations for systems that could not be updated.
Mitsubishi Electric published PSIRT advisory 2022-001 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event apart from the already tracked 2022-006, 2022-016, 2023-006, 2024-004, and 2025-011 notices.
CISA published advisory ICSA-22-013-07 for CVE-2021-20613 affecting Mitsubishi Electric MELSEC-F Series Ethernet modules, noting remote low-complexity exploitation was possible and that no known public exploits had been reported.
Mitsubishi Electric released firmware version 1.17 or later to address CVE-2021-20613, an improper initialization vulnerability in MELSEC-F Series Ethernet modules that could be exploited remotely to cause a denial-of-service condition requiring a system reset.
Mitsubishi Electric published PSIRT advisory 2022-022 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2022-001, 2022-004, 2022-006, 2022-009, 2022-016, and 2022-018 notices.
Mitsubishi Electric published PSIRT advisory 2022-017 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2022-016, 2022-018, and other Mitsubishi Electric PSIRT notices.
Mitsubishi Electric published PSIRT advisory 2022-009 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2022-001, 2022-006, 2022-016, and other Mitsubishi Electric PSIRT notices.
Mitsubishi Electric published PSIRT advisory 2022-004 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2022-001, 2022-006, 2022-009, 2022-016, and 2022-018 notices.
Mitsubishi Electric published PSIRT advisory 2022-006 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event apart from the already tracked 2021-011, CVE-2021-20613, and CVE-2023-4699 notices.
Mitsubishi Electric published PSIRT advisory 2021-019 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2021-002, 2021-003, 2021-006, 2021-011, and later PSIRT notices.
Mitsubishi Electric published PSIRT advisory 2021-015 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2021-002, 2021-003, 2021-006, 2021-011, and 2021-019 notices.
Mitsubishi Electric published PSIRT advisory 2021-011 for a separate product vulnerability not currently represented in the timeline. The advisory marks a new vendor disclosure event distinct from the previously tracked CVE-2021-20613 and CVE-2023-4699 notices.
CISA published advisory ICSA-21-201-01 for CVE-2021-20596, a remotely exploitable NULL pointer dereference vulnerability affecting Mitsubishi Electric MELSEC-F Series Ethernet interface blocks. The flaw could be triggered by specially crafted packets to cause a denial-of-service condition requiring a system reset, and the advisory noted no known public exploits.
Mitsubishi Electric published PSIRT advisory 2021-002 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2021-003, 2021-011, and later PSIRT notices.
Mitsubishi Electric published PSIRT advisory 2021-003 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2020-005, 2020-017, 2021-011, 2022-001, 2022-006, 2022-016, 2023-004, 2023-006, 2023-010, 2023-011, 2023-014, 2024-004, 2024-007, and 2025-011 notices.
Mitsubishi Electric published PSIRT advisory 2020-018 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2020-005, 2020-006, 2020-009, 2020-012, 2020-015, and 2020-017 notices.
Mitsubishi Electric published PSIRT advisory 2020-015 for a separate product vulnerability not currently represented in the timeline. This is a distinct vendor disclosure event from the already tracked 2020-005, 2020-012, 2020-017, and later PSIRT notices.
Mitsubishi Electric published PSIRT advisory 2020-013 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2020-012, 2020-015, 2020-016, 2020-017, and other Mitsubishi Electric PSIRT notices.
Mitsubishi Electric published PSIRT advisory 2020-012 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2020-005, 2020-017, 2021-003, 2021-011, 2022-001, 2022-006, 2022-016, 2023-004, 2023-006, 2023-010, 2023-011, 2023-014, 2024-004, 2024-007, and 2025-011 notices.
Mitsubishi Electric published PSIRT advisory 2020-017 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2020-005, 2021-011, 2022-006, 2023-004, 2023-006, 2023-011, 2024-004, and 2025-011 notices.
Mitsubishi Electric published PSIRT advisory 2020-016 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2020-015, 2020-017, 2020-018, and later PSIRT notices.
Mitsubishi Electric published PSIRT advisory 2020-011 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2020-009, 2020-012, 2020-013, 2020-015, 2020-016, 2020-017, and 2020-018 notices.
Mitsubishi Electric published PSIRT advisory 2020-009 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2020-005, 2020-006, 2020-012, 2020-015, and 2020-017 notices.
Mitsubishi Electric published PSIRT advisory 2020-005 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2021-011, 2022-006, 2023-006, 2023-011, 2024-004, and 2025-011 notices.
Mitsubishi Electric published PSIRT advisory 2020-006 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2020-005, 2020-012, 2020-015, 2020-017, and later PSIRT notices.
Mitsubishi Electric published PSIRT advisory 2020-001 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2020-005, 2020-006, 2020-009, 2020-012, 2020-015, 2020-017, and 2020-018 notices.
Mitsubishi Electric published PSIRT advisory 2020-019 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2020-018 and later Mitsubishi Electric PSIRT notices.
Mitsubishi Electric published PSIRT advisory 2021-006 for a separate product vulnerability not currently represented in the timeline. The advisory constitutes a distinct vendor disclosure event from the already tracked 2021-002, 2021-003, 2021-011, and later PSIRT notices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
mitsubishielectric.com
Open sourcemitsubishielectric.com
Open sourcemitsubishielectric.com
Open sourcemitsubishielectric.com
Open sourcemitsubishielectric.com
Open sourcemitsubishielectric.com
Open sourcemitsubishielectric.com
Open sourcemitsubishielectric.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.