ICSA-25-266-02
·
Published 2025-09-23
·
View on CISA ICS-CERT ↗
Mitsubishi Electric MELSEC-Q Series CPU Module
CVSS 6.8
MEDIUM
Risk Summary
Successful exploitation of this vulnerability could allow an attacker to cause a denial of service (DoS).
CVEs (1)
Remediations
- Mitsubishi Electric has released the fixed version as shown below, but updating the product to the fixed version is currently unavailable. Consider migrating to the successor model, MELSEC iQ-R Series.
- MELSEC-QSeries Q03UDVCPU: The first 5 digits of serial No. '27082' or later.
- MELSEC-QSeries Q04UDVCPU: The first 5 digits of serial No. '27082' or later.
- MELSEC-QSeries Q06UDVCPU: The first 5 digits of serial No. '27082' or later.
- MELSEC-QSeries Q13UDVCPU: The first 5 digits of serial No. '27082' or later.
- MELSEC-QSeries Q26UDVCPU: The first 5 digits of serial No. '27082' or later.
- MELSEC-QSeries Q04UDPVCPU: The first 5 digits of serial No. '27082' or later.
- MELSEC-QSeries Q06UDPVCPU: The first 5 digits of serial No. '27082' or later.
- MELSEC-QSeries Q13UDPVCPU: The first 5 digits of serial No. '27082' or later.
- MELSEC-QSeries Q26UDPVCPU: The first 5 digits of serial No. '27082' or later.
- Mitsubishi Electric recommends users employ the following mitigation measures to minimize the risk of vulnerability exploit.
- Use a firewall or virtual private network (VPN), etc. to prevent unauthorized access when Internet access is required.
- Use within a LAN and block access from untrusted networks and hosts through firewalls.
- Restrict physical access to the affected products, as well as to computers and network devices that can be connected to those products.
- See Mitsubishi Electric's security bulletin for more information.
Affected Vendors
Mitsubishi Electric
Affected Products (9)
Mitsubishi Electric
·
MELSEC-Q Series Q03UDVCPU
>=The_first_5_digits_of_serial_No._'24082'|<'27081'
Mitsubishi Electric
·
MELSEC-Q Series Q04UDVCPU
>=The_first_5_digits_of_serial_No._'24082'|<'27081'
Mitsubishi Electric
·
MELSEC-Q Series Q06UDVCPU
>=The_first_5_digits_of_serial_No._'24082'|<'27081'
Mitsubishi Electric
·
MELSEC-Q Series Q13UDVCPU
>=The_first_5_digits_of_serial_No._'24082'|<'27081'
Mitsubishi Electric
·
MELSEC-Q Series Q26UDVCPU
>=The_first_5_digits_of_serial_No._'24082'|<'27081'
Mitsubishi Electric
·
MELSEC-Q Series Q04UDPVCPU
>=The_first_5_digits_of_serial_No._'24082'|<'27081'
Mitsubishi Electric
·
MELSEC-Q Series Q06UDPVCPU
>=The_first_5_digits_of_serial_No._'24082'|<'27081'
Mitsubishi Electric
·
MELSEC-Q Series Q13UDPVCPU
>=The_first_5_digits_of_serial_No._'24082'|<'27081'
Mitsubishi Electric
·
MELSEC-Q Series Q26UDPVCPU
>=The_first_5_digits_of_serial_No._'24082'|<'27081'
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more