CVE Database
/

CVE-2025-2399

Back to search

CVE-2025-2399

Published: Mar 10, 2026

Modified: Mar 24, 2026

PUBLISHED

CVSS v3.1

5.9

MEDIUM

Description

Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric CNC M800V Series M800VW and M800VS, M80V Series M80V and M80VW, M800 Series M800W and M800S, M80 Series M80 and M80W, E80 Series E80, C80 Series C80, M700V Series M750VW, M720VW, 730VW, M720VS, M730VS, and M750VS, M70V Series M70V, E70 Series E70, and Software Tools NC Trainer2 and NC Trainer2 plus allows a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition by sending specially crafted packets to TCP port 683.

VendorProductVersions

Mitsubishi Electric Corporation

Mitsubishi Electric CNC M800V Series M800VW

affected
System Number BND-2051W000 versions BB and prior

Mitsubishi Electric Corporation

Mitsubishi Electric CNC M800V Series M800VS

affected
System Number BND-2052W000 versions BB and prior

Mitsubishi Electric Corporation

Mitsubishi Electric CNC M80V Series M80V

affected
System Number BND-2053W000 versions BB and prior

Mitsubishi Electric Corporation

Mitsubishi Electric CNC M80V Series M80VW

affected
System Number BND-2054W000 versions BB and prior

Mitsubishi Electric Corporation

Mitsubishi Electric CNC M800 Series M800W

affected
System Number BND-2005W000 versions FM and prior

Mitsubishi Electric Corporation

Mitsubishi Electric CNC M800 Series M800S

affected
System Number BND-2006W000 versions FM and prior

Mitsubishi Electric Corporation

Mitsubishi Electric CNC M80 Series M80

affected
System Number BND-2007W000 versions FM and prior

Mitsubishi Electric Corporation

Mitsubishi Electric CNC M80 Series M80W

affected
System Number BND-2008W000 versions FM and prior

Mitsubishi Electric Corporation

Mitsubishi Electric CNC E80 Series E80

affected
System Number BND-2009W000 versions FM and prior

Mitsubishi Electric Corporation

Mitsubishi Electric CNC C80 Series C80

affected
System Number BND-2036W000 all versions

Mitsubishi Electric Corporation

Mitsubishi Electric CNC M700V Series M750VW

affected
System Number BND-1015W002 all versions

Mitsubishi Electric Corporation

Mitsubishi Electric CNC M700V Series M720VW

affected
System Number BND-1015W000 all versions

Mitsubishi Electric Corporation

Mitsubishi Electric CNC M700V Series M730VW

affected
System Number BND-1015W000 all versions

Mitsubishi Electric Corporation

Mitsubishi Electric CNC M700V Series M720VS

affected
System Number BND-1012W000 all versions

Mitsubishi Electric Corporation

Mitsubishi Electric CNC M700V Series M730VS

affected
System Number BND-1012W000 all versions

Mitsubishi Electric Corporation

Mitsubishi Electric CNC M700V Series M750VS

affected
System Number BND-1012W002 all versions

Mitsubishi Electric Corporation

Mitsubishi Electric CNC M70V Series M70V

affected
System Number BND-1018W000 all versions

Mitsubishi Electric Corporation

Mitsubishi Electric CNC E70 Series E70

affected
System Number BND-1022W000 all versions

Mitsubishi Electric Corporation

Mitsubishi Electric CNC Software Tools NC Trainer2

affected
System Number BND-1802W000 all versions

Mitsubishi Electric Corporation

Mitsubishi Electric CNC Software Tools NC Trainer2 plus

affected
System Number BND-1803W000 all versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Network

Attack Complexity

High

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now