High-Severity DoS Vulnerability Discovered in Mitsubishi Electric's MELSEC Modules
Mitsubishi Electric's MELSEC iQ-F Series FX5-ENET/IP Ethernet Module is vulnerable to a denial-of-service (DoS) attack due to an Expected Behavior Violation. Attackers can exploit this by sending numerous communication packets, causing the module to stop functioning properly. The CVSS score of 8.7 indicates high severity. Defenders should update affected systems or apply recommended mitigations immediately.
Summary
Mitsubishi Electric has disclosed a critical vulnerability affecting its MELSEC iQ-F Series FX5-ENET/IP Ethernet Module (CVE-2026-8806). This flaw allows attackers to disrupt the module's operations by flooding it with communication packets, leading to a denial-of-service condition. The CVSS score of 8.7 underscores the severity of this vulnerability, which can significantly impact industrial control systems relying on these modules.
What Happened
The vulnerability stems from an Expected Behavior Violation in the FX5-ENET/IP Ethernet Module. Attackers can exploit this by sending a large number of communication packets to the module's Ethernet port within a short period. This action overwhelms the module, increasing its processing load and preventing it from performing anomaly-detection processes. As a result, the module's communication functions cease, leading to a denial-of-service condition.
Technical Details
The vulnerability is characterized by an Expected Behavior Violation where the module fails to handle excessive communication packets efficiently. The attack involves sending numerous packets in quick succession, which increases the processing load on the module. This overload prevents the module from executing its internal anomaly-detection processes, ultimately causing a halt in its communication functions.
Affected Products and Fixed Versions
The vulnerability affects all versions of the Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module. No specific version is immune to this flaw, making it critical for all users of this product to take immediate action.
| Product | Version | Vulnerability |
|---|---|---|
| MELSEC iQ-F Series FX5-ENET/IP Ethernet Module | All versions | CVE-2026-8806 |
Exploitation Status
The vulnerability has been publicly disclosed, and a proof-of-concept exploit is available. Attackers can leverage this flaw to disrupt the operations of affected modules, emphasizing the need for immediate remediation.
Indicators of Compromise
Currently, specific indicators of compromise (IOCs) have not been detailed in the advisory. However, monitoring for unusual network traffic patterns targeting the Ethernet ports of these modules could serve as an early warning sign.
Detection Opportunities
Organizations can detect potential exploitation attempts by monitoring network traffic to their MELSEC iQ-F Series FX5-ENET/IP Ethernet Modules. Anomalies such as a sudden spike in communication packets directed at these devices should trigger further investigation.
Timeline
The vulnerability was disclosed on June 18, 2026, through multiple advisories from CISA and Mitsubishi Electric. The public disclosure of the proof-of-concept exploit followed shortly after.
| Date | Event |
|---|---|
| Jun 18, 2026 | Disclosure by Mitsubishi Electric and CISA |
Why This Matters for Defenders
The high CVSS score of 8.7 indicates that this vulnerability poses a significant risk to industrial control systems using the affected modules. A successful exploitation can lead to operational disruptions, potentially affecting critical infrastructure. Immediate action is required to mitigate the risk.
What Remains Unclear
While the technical details and impact of the vulnerability are clear, specific indicators of compromise have not been provided. Additionally, there is no patch available for CVE-2026-8806, leaving organizations reliant on workarounds.
Defender Guidance
Defenders should take immediate steps to mitigate the risk posed by this vulnerability:
- Monitor Network Traffic: Implement network monitoring to detect unusual traffic patterns targeting the Ethernet ports of MELSEC iQ-F Series FX5-ENET/IP modules.
- Apply Workarounds: Follow the recommended workarounds provided by Mitsubishi Electric to minimize the impact of the vulnerability until a patch is available.
- Stay Informed: Regularly check for updates from Mitsubishi Electric and CISA regarding this vulnerability.
By taking these actions, defenders can reduce the risk of exploitation and maintain operational stability in their industrial control systems.
