Our takeCISA reports active exploitation of an out-of-bounds read in Mitsubishi Electric M800VW and M800VS CNC systems that can cause denial of service. Update immediately if you operate the affected versions.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:CISA reports active exploitation of an out-of-bounds read (CVE-2025-2399) in Mitsubishi Electric M800VW (<=BB) and M800VS CNC systems that can be triggered remotely to cause denial of service. Update immediately or segment/isolate affected CNC controllers if you operate them.
What this means for you — Lean IT orgs:If you run Mitsubishi Electric M800VW or M800VS CNC machines, update the firmware right away. This flaw lets a remote attacker crash the system; check with your machine vendor or integrator if you are unsure how to patch.
What this means for you — MSP:Audit client environments for any Mitsubishi Electric M800VW (<=BB) or M800VS CNC deployments and apply the vendor update immediately. Most clients will be unaffected unless they operate industrial automation equipment.
What this means for you — Researcher:CISA confirms active exploitation of CVE-2025-2399 (out-of-bounds read leading to DoS) in Mitsubishi Electric M800VW and M800VS CNC Series. See the updated ICSA-26-078-05 advisory for affected part numbers and mitigations.