CISA has published an advisory for CVE-2026-13584, a high-severity flaw in Mitsubishi Electric’s CC-Link IE TSN communication protocol that can let an attacker on the same network segment tamper with industrial control traffic. The practical risk is disruption or incorrect operation of connected equipment—including controllers, remote I/O, servo systems, inverters, robots, HMIs, and Windows-based engineering software.
The advisory, republished by CISA from Mitsubishi Electric’s 2026-005 security notice on July 30, affects a very broad range of CC-Link IE TSN-enabled products across the MELSEC, MELSERVO, MELIPC, GOT3000, and FR inverter families. Mitsubishi Electric lists all versions of the affected products as vulnerable and says there is no fix planned.
The vulnerability is rated 7.1 High under CVSS 3.1. It stems from improper enforcement of message integrity in the protocol, meaning specially crafted packets may be accepted under particular timing conditions. An unauthenticated attacker requires adjacent-network access, not credentials or user interaction, to alter control input or output values and potentially trigger a denial-of-service condition.
This is not limited to a single PLC or firmware branch. CISA’s affected-product inventory includes MELSEC MX-R and MX-F controllers; RJ71GN11 master/local modules; CC-Link IE TSN interface boards; RD78 motion modules; NZ2 remote I/O, safety, analog, digital, FPGA, bridge, and coupler modules; MELSERVO-J5 and MELSERVO-JET drives; FR-A800, FR-F800, and FR-E800 inverter interfaces; and CR800-D robot controller networking hardware.
The scope also reaches infrastructure surrounding the control plane. Mitsubishi Electric lists MELIPC MI2332-W and MI2532-W industrial computers, several GOT3000 HMI models, the GT25-J71GN13-T2 communication unit, Motion Control Software SWM-G, MELSOFT VIMA, and SW1DND-CCIETCT-M, CC-Link IE TSN Communication Software for Windows.
For Windows administrators supporting plants or machine builders, that last category matters: a Windows engineering workstation may not be the vulnerable endpoint itself, but it can be the operational gateway used to configure, monitor, and troubleshoot an affected TSN environment.
The vendor recommends restricting physical access to control panels and Ethernet ports, blocking communications from untrusted networks and hosts through firewalls or equivalent controls, and tightly configuring credentials and privileges on boundary network equipment. CISA separately advises keeping control systems off the public internet, isolating them from business networks, and performing impact analysis before deploying mitigations.
The vulnerability was reported to Mitsubishi Electric by researchers Alessandro Di Pinto, Giovanni Dini Gentilini, Luca Cremona, and Gabriele Quagliarella of Nozomi Networks. For operators, the near-term task is clear: inventory every CC-Link IE TSN-connected asset, validate network segmentation, and ensure no untrusted device can join or inject traffic into the production segment.
The advisory, republished by CISA from Mitsubishi Electric’s 2026-005 security notice on July 30, affects a very broad range of CC-Link IE TSN-enabled products across the MELSEC, MELSERVO, MELIPC, GOT3000, and FR inverter families. Mitsubishi Electric lists all versions of the affected products as vulnerable and says there is no fix planned.
The vulnerability is rated 7.1 High under CVSS 3.1. It stems from improper enforcement of message integrity in the protocol, meaning specially crafted packets may be accepted under particular timing conditions. An unauthenticated attacker requires adjacent-network access, not credentials or user interaction, to alter control input or output values and potentially trigger a denial-of-service condition.
A protocol-level problem across industrial hardware
This is not limited to a single PLC or firmware branch. CISA’s affected-product inventory includes MELSEC MX-R and MX-F controllers; RJ71GN11 master/local modules; CC-Link IE TSN interface boards; RD78 motion modules; NZ2 remote I/O, safety, analog, digital, FPGA, bridge, and coupler modules; MELSERVO-J5 and MELSERVO-JET drives; FR-A800, FR-F800, and FR-E800 inverter interfaces; and CR800-D robot controller networking hardware.The scope also reaches infrastructure surrounding the control plane. Mitsubishi Electric lists MELIPC MI2332-W and MI2532-W industrial computers, several GOT3000 HMI models, the GT25-J71GN13-T2 communication unit, Motion Control Software SWM-G, MELSOFT VIMA, and SW1DND-CCIETCT-M, CC-Link IE TSN Communication Software for Windows.
For Windows administrators supporting plants or machine builders, that last category matters: a Windows engineering workstation may not be the vulnerable endpoint itself, but it can be the operational gateway used to configure, monitor, and troubleshoot an affected TSN environment.
Segmentation is the immediate control
Mitsubishi Electric’s mitigation is chiefly architectural because no vendor patch is planned. Organizations should treat the CC-Link IE TSN segment as a trusted operational network rather than a broadly reachable Ethernet environment.The vendor recommends restricting physical access to control panels and Ethernet ports, blocking communications from untrusted networks and hosts through firewalls or equivalent controls, and tightly configuring credentials and privileges on boundary network equipment. CISA separately advises keeping control systems off the public internet, isolating them from business networks, and performing impact analysis before deploying mitigations.
The vulnerability was reported to Mitsubishi Electric by researchers Alessandro Di Pinto, Giovanni Dini Gentilini, Luca Cremona, and Gabriele Quagliarella of Nozomi Networks. For operators, the near-term task is clear: inventory every CC-Link IE TSN-connected asset, validate network segmentation, and ensure no untrusted device can join or inject traffic into the production segment.
References
- Primary source: CISA
Published: 2026-07-30T12:00:00+00:00