Improper message integrity in Mitsubishi Electric MELSEC MX controllers enables control data manipulation
An improper message integrity flaw in several Mitsubishi Electric MELSEC MX controllers allows attackers on a CC-Link IE TSN network to manipulate control data. This vulnerability can lead to denial-of-service conditions or incorrect device operation. Defenders should isolate industrial networks and verify the integrity of communication channels.
Summary
A high-severity vulnerability has been disclosed affecting a wide array of Mitsubishi Electric MELSEC MX controllers and related industrial components. The flaw, identified as CVE-2026-13584, stems from improper enforcement of message integrity during transmission across specific communication channels.
If an attacker gains access to a CC-Link IE TSN network, they can inject specially crafted packets under specific timing conditions. This interference allows for the tampering of control input/output values, which may result in a denial-of-service (DoS) state or cause industrial hardware to operate incorrectly.
Technical Details
The vulnerability resides in how the communication channel handles message integrity. Because the system fails to properly validate the integrity of incoming messages during transmission, it is susceptible to manipulation by any actor with network access.
The impact is highly dependent on the specific hardware being targeted. The flaw affects various modules including:
- MELSEC MX Controller MX-R and MX-F models
- CC-Link IE TSN interface boards and expansion units
- Motion modules and Control Boards
- Inverters (FR-A800/F800/E800 Series)
- Industrial Robot CR800-D series controllers
- Various LSI devices and software kits used for Master/Local module communication
An attacker targeting these components can disrupt the control function by altering the data that dictates how a machine or motor responds to commands.
Affected Products
The vulnerability impacts a broad spectrum of Mitsubishi Electric industrial products, specifically those utilizing CC-Link IE TSN or related communication protocols.
| Product Category | Affected Models/Series |
|---|---|
| Controllers | MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model |
| Motion & Control | Motion module, Motion Control Software, AC Servo MELSERVO-J5, AC Servo MELSERVO-JET |
| Communication Hardware | CC-Link IE TSN interface board, CC-Link IE TSN expansion unit, CC-Link IE TSN-CC-Link IE Field Network bridge module |
| Industrial Computing | Industrial Computer MELIPC series, GOT3000 Series |
| Specialized Modules | Analog-Digital converter module, Digital-Analog converter module, Tension meter |
Why this matters for defenders
For operators of industrial automation lines, this vulnerability represents a direct risk to process stability. Because the attack relies on "specific timing conditions," an attacker must have precise knowledge of the network traffic or be able to observe it to successfully inject the tampered packets.
The primary consequence is the loss of predictable control. If a controller receives manipulated input/output values, it may trigger an emergency stop (DoS) or, more dangerously, execute unintended physical movements that deviate from the programmed logic. This makes the integrity of the CC-Link IE TSN network a critical security boundary.
Defender guidance
Securing these environments requires focusing on network segmentation and traffic validation.
- Isolate Industrial Networks: Ensure that CC-Link IE TSN networks are strictly isolated from corporate networks and the public internet. Access to these control networks should be restricted to authorized engineering workstations only.
- Monitor Network Timing and Traffic: Since the exploit relies on specific timing, monitoring for unusual network jitter or unexpected packet injection patterns may provide early warning of an attempted manipulation.
- Verify Communication Integrity: Where possible, implement secondary validation methods for critical control signals to ensure that the data received by a module matches the intended command sent by the master controller.
