# Mitsubishi Electric's Critical EtherNet/IP Flaw Exposes Factory Networks to Remote Denial-of-Service Attacks
## The Threat
Mitsubishi Electric has disclosed a critical vulnerability in its widely deployed MELSEC iQ-F Series industrial controllers that allows remote attackers to crash the devices over the network without authentication. The flaw—an integer overflow vulnerability in the EtherNet/IP communication module—can be exploited by rapidly flooding the controller with TCP connection requests, causing internal memory corruption and a complete denial of service.
The vulnerability affects the FX5-EIP EtherNet/IP module, a key component in Mitsubishi's popular MELSEC iQ-F programmable logic controllers (PLCs). These systems are critical components in manufacturing environments worldwide, used to control everything from assembly lines to process automation in chemical plants, refineries, and discrete manufacturing facilities. The FX5-EIP module enables remote communication and monitoring capabilities—the same feature that introduces the attack surface.
An attacker positioned on the network can exploit this flaw with minimal effort. The attack requires no authentication, no user interaction, and no system-level access. By sending a carefully timed barrage of connection requests to the vulnerable module's network port, an attacker triggers an integer wraparound in the module's connection counter, causing it to mismanage memory and crash. For industrial organizations, even minutes of downtime can translate to significant financial losses and safety risks. In sectors like manufacturing and chemical processing, an unexpected shutdown could have cascading consequences far beyond the single device.
## Severity and Impact
| Attribute | Details |
|---|---|
| CVE Identifier | CVE-2026-8805 |
| CVSS v3.1 Score | 7.5 (HIGH) |
| CVSS v4.0 Score | 8.7 (HIGH) |
| CVSS Vector (v3.1) | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| CVSS Vector (v4.0) | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
| Vulnerability Type | Integer Overflow or Wraparound (CWE-190) |
| Attack Vector | Network (AV:N) — exploitable remotely |
| Attack Complexity | Low (AC:L) — no special conditions required |
| Authentication | None (PR:N) — no credentials needed |
| Impact | Availability only (A:H) — causes denial of service |
| Affected Component | EtherNet/IP communication function |
## Affected Products
- FX5-EIP EtherNet/IP Module FX5-EIP version 1.000 and earlier
Organizations running MELSEC iQ-F controllers with EtherNet/IP capabilities deployed before the fix was released are vulnerable. These controllers are common in manufacturing, utilities, and process industries globally. Mitsubishi Electric's extensive customer base across critical infrastructure sectors means this vulnerability has potentially widespread exposure.
## Mitigations
Immediate Action: Apply the Vendor Fix
Mitsubishi Electric released fixed version 1.001 or later for the FX5-EIP EtherNet/IP module. Organizations should prioritize updating affected devices to the patched version immediately. Updated firmware is available through Mitsubishi Electric's download portal at https://www.mitsubishielectric.com/fa/download/index.html.
For Organizations Unable to Patch Immediately:
1. Network Segmentation & Firewall Controls
- Isolate affected MELSEC iQ-F controllers on dedicated subnets separate from general corporate networks
- Implement firewall rules to block inbound TCP connections to the device from untrusted networks and external hosts
- Where internet access is required, route traffic exclusively through VPN tunnels with strict access control lists
2. Utilize Built-in IP Filtering
- Enable the IP filter function available in the affected products (documented in Section 13.1 of the MELSEC iQ-F FX5 User's Manual for Communication)
- Whitelist only known, trusted hosts that legitimately need to communicate with the controller
- Block all other sources at the device level
3. Physical & Endpoint Security
- Restrict physical access to affected controllers and to PCs and network devices that connect to them
- Install and maintain current anti-virus and anti-malware software on any PC that communicates with the vulnerable devices
- Monitor for suspicious connection patterns or unexpected network traffic directed at the controllers
4. Monitoring & Detection
- Log and monitor all network connections to the affected modules
- Alert on unusual spikes in connection attempts or failed TCP handshakes
- Implement intrusion detection rules that flag rapid connection floods to known MELSEC devices
## References
---
## HackWire Analysis
This vulnerability highlights a troubling pattern in industrial control systems: network connectivity introduces modern attack surfaces to devices designed with physical-world assumptions. The EtherNet/IP protocol brought remote monitoring and diagnostics to manufacturing floors—undeniably valuable—but the MELSEC iQ-F module's failure to properly handle connection state management exposes a fundamental flaw in how legacy industrial protocols handle resource exhaustion.
What makes this particularly concerning is the *ease of exploitation*. This isn't a complex attack chain or a vulnerability requiring deep protocol knowledge. An attacker with basic networking tools can trigger a denial of service with a handful of commands. No privilege escalation, no authentication bypass, no social engineering. A motivated adversary could weaponize this as part of an industrial espionage campaign or a disruptive attack against manufacturing sectors.
The broader context matters: manufacturing and critical infrastructure continue to lag behind enterprise IT in security patching velocity. A CVSS 7.5+ vulnerability in a PLC affects organizations with stringent uptime requirements and complex change management procedures. Factories cannot simply reboot controllers during production shifts. This friction is precisely why adversaries target industrial systems—the business costs of patching are real, and defenders often lag behind the threat timeline.
The mitigations Mitsubishi prescribed—network segmentation, IP filtering, and VPN tunneling—are sound defensive measures, but they're reactive bandages. The real issue is that industrial protocols weren't architected for hostile networks. As manufacturing systems increasingly connect to corporate networks and the internet for monitoring and predictive maintenance, this disconnect between legacy design assumptions and modern threat models will continue to fuel incidents. Organizations deploying MELSEC controllers should treat this as a forcing function to audit their OT network architecture and prioritize segmentation before the next vulnerability surfaces.
— HackWire Editorial
## Related Coverage