CVE-2026-13584: Information tampering and Denial-of-service (DoS) vulnerability in CC-Link IE TSN communication protocol

Published Jul 30, 2026
·
Updated

Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, Motion Control Board, Block-type remote module, Block-type remote module with safety functions, Analog-Digital converter module, Digital-Analog converter module, CC-Link IE TSN compatible coupler, FPGA module, Tension meter, AC Servo MELSERVO-J5, AC Servo MELSERVO-JET, Liner Track System MTR-S series Linear track control module, Inverter FR-A800/F800/E800 Series, Industrial Robot CR800-D series controller Network Base Card, CC-Link IE TSN expansion unit, CC-Link IE TSN-CC-Link IE Field Network bridge module, CC-Link IE TSN-AnyWireASLINK bridge module, Energy Measuring Unit CC-Link IE TSN Communication Unit, Industrial Computer MELIPC series, GOT3000 Series, CC-Link IE TSN Communication Unit, Motion Control Software, CC-Link IE TSN Communication Software for Windows, Analysis Support Software MELSOFT VIMA, Master/Local module Designated communication LSI DeviceKit, Master/Local module Designated communication LSI, Remote Station Communication LSI with GbE-PHY, CC-Link IE TSN Master/Local module Designated communication LSI SDK, and Remote station software development kit allows an attacker with access to a CC-Link IE TSN network to tamper with communication data (control input/output values) by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.

Affected Software

33 affected components
Mitsubishi Electric MELSEC MX Controller MX-R
Mitsubishi Electric MELSEC MX Controller MX-F
Mitsubishi Electric Master/local module
Mitsubishi Electric CC-Link IE TSN interface board
Mitsubishi Electric Motion module
Mitsubishi Electric Motion Control Board
Mitsubishi Electric Block-type remote module
Mitsubishi Electric Block-type remote module with safety functions
Mitsubishi Electric Analog-Digital converter module
Mitsubishi Electric Digital-Analog converter module
Mitsubishi Electric CC-Link IE TSN compatible coupler
Mitsubishi Electric FPGA module
Mitsubishi Electric Tension meter
Mitsubishi Electric AC Servo MELSERVO-J5
Mitsubishi Electric AC Servo MELSERVO-JET
Mitsubishi Electric Liner Track System MTR-S series Linear track control module
Mitsubishi Electric Inverter FR-A800/F800/E800 Series
Mitsubishi Electric Industrial Robot CR800-D series controller Network Base Card
Mitsubishi Electric CC-Link IE TSN expansion unit
Mitsubishi Electric CC-Link IE TSN-CC-Link IE Field Network bridge module
Mitsubishi Electric CC-Link IE TSN-AnyWireASLINK bridge module
Mitsubishi Electric Energy Measuring Unit CC-Link IE TSN Communication Unit
Mitsubishi Electric Industrial Computer MELIPC series
Mitsubishi Electric GOT3000 Series
Mitsubishi Electric CC-Link IE TSN Communication Unit
Mitsubishi Electric Motion Control Software
Mitsubishi Electric CC-Link IE TSN Communication Software for Windows
Mitsubishi Electric Analysis Support Software MELSOFT VIMA
Mitsubishi Electric Master/Local module Designated communication LSI DeviceKit
Mitsubishi Electric Master/Local module Designated communication LSI
Mitsubishi Electric Remote Station Communication LSI with GbE-PHY
Mitsubishi Electric CC-Link IE TSN Master/Local module Designated communication LSI SDK
Mitsubishi Electric Remote station software development kit

Event History

Jul 30, 2026
CVE Published
via MITRE·06:44 AM
Data Sourced
via MITRE·06:44 AM
DescriptionWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-13584?

The severity of CVE-2026-13584 is classified as high with a CVSS score of 7.1.

2

What types of vulnerabilities are associated with CVE-2026-13584?

CVE-2026-13584 is associated with information tampering and Denial-of-service (DoS) vulnerabilities.

3

How do I fix CVE-2026-13584?

To fix CVE-2026-13584, apply the security patches provided by Mitsubishi Electric for affected products.

4

Which devices are affected by CVE-2026-13584?

CVE-2026-13584 affects various Mitsubishi Electric MELSEC MX Controllers and related modules.

5

What impact does CVE-2026-13584 have on system security?

CVE-2026-13584 can lead to compromised message integrity and potential disruptions in communication, affecting overall system reliability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203