CVE-2025-3755: Information Disclosure and Denial-of-Service(DoS) Vulnerability in MELSEC iQ-F Series CPU module
Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU modules allows a remote unauthenticated attacker to read information in the product, to cause a Denial-of-Service (DoS) condition in MELSOFT connection, or to stop the operation of the CPU module (causing a DoS condtion on the CPU module), by sending specially crafted packets. The product is needed to reset for recovery.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3755?
CVE-2025-3755 is rated as a high severity vulnerability due to its ability to allow remote unauthenticated access and potential Denial-of-Service conditions.
How do I fix CVE-2025-3755?
To fix CVE-2025-3755, implement the recommended patches and updates provided by Mitsubishi Electric for the MELSEC iQ-F Series CPU modules.
What types of attacks can be executed using CVE-2025-3755?
Exploiting CVE-2025-3755 can enable attackers to read sensitive information and create Denial-of-Service (DoS) conditions.
Who is affected by CVE-2025-3755?
CVE-2025-3755 affects users of the Mitsubishi Electric MELSEC iQ-F Series CPU modules.
Can CVE-2025-3755 be exploited remotely?
Yes, CVE-2025-3755 can be exploited by remote unauthenticated attackers, increasing its risk for users.