CISA issued updated advisories for multiple Mitsubishi Electric industrial control system products used in the Critical Manufacturing sector, detailing vulnerabilities that could let remote attackers disrupt operations, impersonate trusted devices, or execute malicious code. The most severe issue, CVE-2023-3346, is a critical classic buffer overflow in numerous Mitsubishi Electric CNC Series products with a CVSS v3 9.8 score; CISA said specially crafted packets could trigger denial of service and enable unauthenticated remote code execution, with some affected systems requiring a reset to recover.
Separate advisories also covered CVE-2020-16226, a predictable-value weakness affecting a broad range of Mitsubishi Electric automation products that could allow device impersonation, TCP session hijacking, and possible remote command execution, and two flaws in CC-Link IE TSN Industrial Managed Switch models NZ2MHG-TSNT8F2 and NZ2MHG-TSNT4: CVE-2022-4304, an observable timing discrepancy that may disclose information via crafted packets, and CVE-2022-4450, a double-free bug that could cause denial of service through a malicious certificate import. Mitsubishi Electric has released firmware or fixed versions for affected products and urged operators to upgrade, segment control networks, limit internet exposure, and use firewalls or VPNs for remote access; CISA said it had no evidence of public exploitation targeting these flaws at the time of publication.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
17 events from the most recent confirmed update back to the earliest known activity.
Mitsubishi Electric published a new PSIRT vulnerability advisory identified as 2025-022. Based on the provided reference metadata, this appears to be a distinct vendor disclosure not already captured in the timeline, though specific affected products and vulnerability details are not available from the supplied content.
CISA published advisory ICSA-24-200-01 covering CVE-2023-4807, an improper verification of cryptographic signature vulnerability in OpenSSL's POLY1305 MAC implementation affecting Mitsubishi Electric MELSOFT MaiLab and MELSOFT VIXIO. Mitsubishi Electric listed fixed versions for both product lines, and CISA said there was no known public exploitation at the time.
CISA published Update G for advisory ICSA-20-245-01 covering CVE-2020-16226, a predictable-value vulnerability affecting many Mitsubishi Electric industrial products. The flaw could let an attacker impersonate devices, hijack TCP sessions, and potentially achieve remote command execution; Mitsubishi Electric provided fixed versions for many products and mitigation guidance.
CISA published Update A for advisory ICSA-23-278-03 on two vulnerabilities in Mitsubishi Electric CC-Link IE TSN Industrial Managed Switch models NZ2MHG-TSNT8F2 and NZ2MHG-TSNT4 running firmware 05 and earlier. The issues, CVE-2022-4304 and CVE-2022-4450, could enable information disclosure or denial of service, and Mitsubishi Electric recommended upgrading to firmware version 06 or later.
CISA issued advisory ICSA-23-208-03 covering CVE-2023-3346 in Mitsubishi Electric CNC Series devices used in critical manufacturing worldwide. CISA said there was no known public exploitation at the time and urged standard ICS hardening measures, including minimizing internet exposure.
Mitsubishi Electric disclosed CVE-2023-3346, a critical classic buffer overflow affecting multiple CNC Series products that could allow unauthenticated remote code execution or denial of service via specially crafted packets. The company released fixed versions for most affected products and recommended segmentation, firewall/VPN protection, and access restrictions.
CISA published advisory ICSA-23-285-13 covering CVE-2023-4562, an improper authentication vulnerability affecting Mitsubishi Electric MELSEC-F Series programmable controllers used with specific Ethernet communication adapters and blocks. The flaw could allow a remote unauthenticated attacker to obtain or modify sequence programs and alter device data; CISA and Mitsubishi Electric recommended segmentation, firewall or VPN protection, trusted-LAN restrictions, and limiting physical access, with no known public exploitation reported.
Mitsubishi Electric published PSIRT vulnerability advisory 2023-013. Based on the supplied reference metadata, this appears to be a distinct vendor disclosure not already captured in the timeline, though specific affected products and technical details are not available from the provided content.
CISA published Update D for advisory ICSA-20-212-02 covering CVE-2020-14496, a permission issues vulnerability affecting numerous Mitsubishi Electric Factory Automation Engineering Software products. Mitsubishi Electric provided fixes for many products, said MELSEC WinCPU Setting Utility would not be patched and should be migrated, and recommended standard ICS mitigations; no known public exploitation was reported.
CISA published Update C for advisory ICSA-20-212-03 covering path traversal vulnerabilities affecting Mitsubishi Electric Factory Automation Products. The advisory documented a separate set of flaws from the other Mitsubishi Electric advisories already in the timeline and provided updated vendor and mitigation information.
CISA published Update A for advisory ICSA-22-139-01 covering two improper input validation vulnerabilities in Mitsubishi Electric MELSEC iQ-F Series CPU modules, including CVE-2022-25161. The flaws could be exploited remotely with crafted packets to cause denial of service, and Mitsubishi Electric provided firmware updates for many affected models while CISA recommended segmentation, firewall/VPN use, and access restrictions.
CISA published advisory ICSA-22-102-02 covering a vulnerability affecting Mitsubishi Electric MELSEC-Q Series C Controller Module products. Based on the reference metadata, this is a distinct Mitsubishi Electric ICS disclosure separate from the other advisories already in the timeline, though the supplied content does not include technical details or impact.
CISA published Update B for advisory ICSA-20-343-02 covering vulnerabilities affecting Mitsubishi Electric GOT and Tension Controller products. Based on the reference metadata, this is a distinct Mitsubishi Electric ICS disclosure separate from the other advisories already in the timeline, though the supplied content does not include technical details or impact.
CISA published advisory ICSA-22-013-01 covering CVE-2021-20612, a lack of administrator control over security affecting Mitsubishi Electric MELSEC-F Series FX3U-ENET Ethernet-Internet block products with firmware 1.14 and earlier. Mitsubishi Electric released fixes in firmware 1.16 or later, and CISA said remote exploitation could cause denial of service with no known public exploits reported.
CISA published Update C for advisory ICSA-20-324-05 covering vulnerabilities affecting Mitsubishi Electric MELSEC iQ-R Series products. Based on the supplied reference metadata, this is a distinct Mitsubishi Electric ICS disclosure not already represented in the timeline, though technical details are not provided in the content.
CISA published Update A for advisory ICSA-20-175-01 covering CVE-2020-5594, a cleartext transmission of sensitive information vulnerability affecting Mitsubishi Electric MELSEC iQ-R, iQ-F, Q, L, and FX Series CPU modules. The flaw could allow information disclosure, data tampering, unauthorized operation, or denial of service; Mitsubishi Electric recommended VPN-based encryption and CISA advised standard ICS network isolation measures, with no known public exploitation reported.
CISA disclosed CVE-2019-13555, an uncontrolled resource consumption vulnerability affecting the FTP server function in Mitsubishi Electric MELSEC-Q Series and MELSEC-L Series CPU modules. Mitsubishi Electric released updated firmware, and CISA recommended firewalling, network isolation, and secure remote access; no known public exploitation was reported.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
16 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourceus-cert.cisa.gov
Open sourcecisa.gov
Open sourcecisa.gov
Open sourceus-cert.cisa.gov
Open sourceus-cert.gov
Open sourcemitsubishielectric.com
Open sourcemitsubishielectric.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.