Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition and execute arbitrary code on the product by sending specially crafted packet
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in MITSUBSHI CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition and execute arbitrary code on the product by sending specially crafted packets. In addition, system reset is required for recovery.
| Vendor | Product | Versions |
|---|---|---|
| Mitsubishi Electric Corporation | MITSUBISHI CNC M800V Series M800VW | System Number BND-2051W000 versions A8 and prior |
| Mitsubishi Electric Corporation | MITSUBISHI CNC M800V Series M800VS | System Number BND-2052W000 versions A8 and prior |
| Mitsubishi Electric Corporation | MITSUBISHI CNC M80V Series M80V | System Number BND-2053W000 versions A8 and prior |
| Mitsubishi Electric Corporation | MITSUBISHI CNC M80V Series M80VW | System Number BND-2054W000 versions A8 and prior |
| Mitsubishi Electric Corporation | MITSUBISHI CNC M800 Series M800W | System Number BND-2005W000 versions FB and prior |
| Mitsubishi Electric Corporation | MITSUBISHI CNC M800 Series M800S | System Number BND-2006W000 versions FB and prior |
| Mitsubishi Electric Corporation | MITSUBISHI CNC M80 Series M80 | System Number BND-2007W000 versions FB and prior |
| Mitsubishi Electric Corporation | MITSUBISHI CNC M80 Series M80W | System Number BND-2008W000 versions FB and prior |
| Mitsubishi Electric Corporation | MITSUBISHI CNC E80 Series E80 | System Number BND-2009W000 versions FB and prior |
| Mitsubishi Electric Corporation | MITSUBISHI CNC C80 Series C80 | System Number BND-2036W000 versions BF and prior |
| Mitsubishi Electric Corporation | MITSUBISHI CNC M700V Series M720VW | System Number BND-1015W000 versions LF and prior |
| Mitsubishi Electric Corporation | MITSUBISHI CNC M700V Series M730VW | System Number BND-1015W000 versions LF and prior |
| Mitsubishi Electric Corporation | MITSUBISHI CNC M700V Series M750VW | System Number BND-1015W002 versions LF and prior |
| Mitsubishi Electric Corporation | MITSUBISHI CNC M700V Series M720VS | System Number BND-1012W000 versions LF and prior |
| Mitsubishi Electric Corporation | MITSUBISHI CNC M700V Series M730VS | System Number BND-1012W000 versions LF and prior |
| Mitsubishi Electric Corporation | MITSUBISHI CNC M700V Series M750VS | System Number BND-1012W002 versions LF and prior |
| Mitsubishi Electric Corporation | MITSUBISHI CNC M70V Series M70V | System Number BND-1018W000 versions LF and prior |
| Mitsubishi Electric Corporation | MITSUBISHI CNC E70 Series E70 | System Number BND-1022W000 versions LF and prior |
| Mitsubishi Electric Corporation | MITSUBISHI CNC IoT Unit Remote Service Gateway Unit | System Number BND-2041W001 versions AD and prior |
| Mitsubishi Electric Corporation | MITSUBISHI CNC IoT Unit Data Acquisition Unit | System Number BND-2041W002 all versions |
Not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS is the best forward-looking signal — see the EPSS row above.
For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.
Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice:
No directly-cited follow-up CVEs in the KB record for this advisory. The references list in section 09 carries the vendor cross-references.