PT-2026-24177 · Mitsubishi · Nc Trainer2 Plus+10
Published
2026-03-10
·
Updated
2026-03-10
·
CVE-2025-2399
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Mitsubishi Electric CNC M800V Series versions M800VW and M800VS
Mitsubishi Electric CNC M80V Series versions M80V and M80VW
Mitsubishi Electric CNC M800 Series versions M800W and M800S
Mitsubishi Electric CNC M80 Series versions M80 and M80W
Mitsubishi Electric CNC E80 Series version E80
Mitsubishi Electric CNC C80 Series version C80
Mitsubishi Electric CNC M700V Series versions M750VW, M720VW, 730VW, M720VS, M730VS, and M750VS
Mitsubishi Electric CNC M70V Series version M70V
Mitsubishi Electric CNC E70 Series version E70
Mitsubishi Electric Software Tools NC Trainer2
Mitsubishi Electric Software Tools NC Trainer2 plus
Description
An improper validation of specified index, position, or offset in input exists in the software. This allows a remote attacker to cause an out-of-bounds read, leading to a denial-of-service condition. The attack is carried out by sending specially crafted packets to TCP port
683.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cnc C80 Series
Cnc E70 Series
Cnc E80 Series
Cnc M700V Series
Cnc M70V Series
Cnc M80 Series
Cnc M800 Series
Cnc M800V Series
Cnc M80V Series
Nc Trainer2
Nc Trainer2 Plus