Our takeCISA reports active exploitation of an out-of-bounds read in Mitsubishi Electric M800VW and M800VS CNC systems that can cause denial of service. Update immediately if you operate the affected versions.Cyber Resilience desk
Sources (1)
- cisa_ics · cisa_ics
What this means for you — Security leader:CISA reports active exploitation of CVE-2025-2399 in Mitsubishi Electric M800VW (<=BB) and M800VS CNC series. Successful attacks can cause an out-of-bounds read leading to denial-of-service. Update immediately if you operate affected versions.
What this means for you — Lean IT orgs:If you run Mitsubishi Electric CNC machines (M800VW or M800VS series), check the version and apply the update right away. This flaw lets a remote attacker crash the controller.
What this means for you — MSP:Check client environments for Mitsubishi Electric M800VW (<=BB) or M800VS CNC controllers and apply the vendor update. This is an actively exploited remote DoS vulnerability.
What this means for you — Researcher:CISA added CVE-2025-2399 (out-of-bounds read leading to DoS) in Mitsubishi Electric CNC M800VW (<=BB) and M800VS to its Known Exploited Vulnerabilities catalog.