# Mitsubishi Electric CC-Link IE TSN Flaw Exposes Industrial Controllers to Network-Level DoS and Data Tampering
## The Threat
CC-Link IE TSN is Mitsubishi Electric's flagship industrial Ethernet protocol — a gigabit, time-sensitive networking standard designed to converge safety, motion, and I/O control traffic onto a single deterministic network. It's the backbone of advanced manufacturing cells, and it's built on the premise that what's on the wire is exactly what was sent. CVE-2026-13584 attacks that premise directly.
An attacker with foothold on the same network segment as affected devices can send specially crafted packets at precise timing windows to tamper with communication data in transit. The result: either a denial-of-service condition that halts the control function, or a subtler failure where the device continues operating — just incorrectly. That second outcome is the more dangerous one. A stopped machine announces itself. A machine running on corrupted process data may not.
The vulnerability covers every version of the affected firmware released to date. There is no "safe" legacy version to fall back to; the flaw is architectural to the protocol implementation across the product family.
## Severity and Impact
| Field | Detail |
|---|---|
| CVE | CVE-2026-13584 |
| CWE | CWE-345 — Insufficient Verification of Data Authenticity |
| CVSS 3.1 Score | 6.5 (Medium) |
| Vector String | AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H |
| Attack Vector | Adjacent Network |
| Attack Complexity | High (timing-dependent) |
| Privileges Required | None |
| User Interaction | None |
| Impact | Integrity (data tampering) + Availability (DoS / incorrect operation) |
The "High" complexity rating reflects the timing requirement — the attacker must synchronize malicious packets to a specific window in the protocol exchange. This is not a script-kiddie drive-by, but it is absolutely within reach of a motivated actor with network access and time to characterize the target environment.
## Affected Products
All versions of the following products are confirmed affected:
MELSEC MX Controller — MX-R Series
MELSEC MX Controller — MX-F Series
Master/Local Modules
CC-Link IE TSN Interface Boards
Motion Modules
Motion Control Board
Block-Type Remote I/O Modules (all versions)
The breadth of affected products — spanning controllers, motion modules, interface boards, and distributed I/O — means this touches every layer of a CC-Link IE TSN network topology simultaneously.
## Mitigations
Mitsubishi Electric has not released a patch at time of publication. Until firmware updates are available, the recommended mitigations are network architecture controls:
## References
---
## HackWire Analysis
The headline number here is the product count — but the more important number is zero: zero safe firmware versions across the entire affected lineup. When a flaw lives in the protocol implementation rather than a discrete feature or configuration, vendors can't quietly push a hotfix to one model. Every affected SKU needs its own validated firmware build, and in industrial environments, firmware updates on production controllers require change control windows, vendor support, and often physical access. That process takes months, not days.
What makes this particularly pointed is the attack surface CC-Link IE TSN occupies. This is not a legacy fieldbus running in a corner of the plant — it's the network that connects motion controllers to robot arms, synchronized servo systems, and safety-critical I/O in modern smart factories. The "incorrect operation" outcome deserves more attention than the DoS case: a manufacturing cell that receives corrupted motion commands or I/O state doesn't necessarily stop. It may produce defective output, damage tooling, or — in the worst case — create unsafe physical conditions before any alarm fires.
The adjacent-network requirement will prompt some defenders to check this off as low exposure. That's the wrong read. Flat OT networks remain common, and initial access through an engineering workstation or HMI on the same segment is a documented path in every major ICS threat actor playbook from TRITON onward. The High complexity rating buys defenders some time; it does not buy them comfort. Automotive, semiconductor, and food & beverage manufacturers running MELSEC-based lines should treat this as a trigger to audit their CC-Link IE TSN network segmentation now, before a patch is available.
— HackWire Editorial
---
## Related Coverage