{"id":"CVE-2026-13584","title":"Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface…","summary":"Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface…","severity":"high","cvss":7.1,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N","cwe":["CWE-924"],"vendor":"Mitsubishi Electric Corporation","product":"MELSEC MX Controller MX-R model MXR300-16","affected":["melsec_mx_controller_mx-r_model_mxr300-16 all versions","melsec_mx_controller_mx-r_model_mxr300-32 all versions","melsec_mx_controller_mx-r_model_mxr300-64 all versions","melsec_mx_controller_mx-r_model_mxr500-128 all versions","melsec_mx_controller_mx-r_model_mxr500-256 all versions","melsec_mx_controller_mx-f_model_mxf100-8-n32 all versions","melsec_mx_controller_mx-f_model_mxf100-8-p32 all versions","melsec_mx_controller_mx-f_model_mxf100-16-n32 all versions","melsec_mx_controller_mx-f_model_mxf100-16-p32 all versions","melsec_mx_controller_mx-f_model_mxf100s-n32 all versions","melsec_mx_controller_mx-f_model_mxf100s-p32 all versions","melsec_mx_controller_mx-f_model_mxf100s-8-n32 all versions","melsec_mx_controller_mx-f_model_mxf100s-8-p32 all versions","melsec_mx_controller_mx-f_model_mxf100s-16-n32 all versions","melsec_mx_controller_mx-f_model_mxf100s-16-p32 all versions","master_local_module_rj71gn11-t2 all versions","master_local_module_rj71gn11-sx all versions","master_local_module_rj71gn11-eip all versions","master_local_module_fx5-cclgn-ms all versions","cc-link_ie_tsn_interface_board_nz81gn11-sx all versions","cc-link_ie_tsn_interface_board_nz81gn11-t2 all versions","motion_module_rd78g4 all versions","motion_module_rd78g8 all versions","motion_module_rd78g16 all versions","motion_module_rd78g64 all versions","motion_module_rd78ghv all versions","motion_module_rd78ghw all versions","motion_module_fx5-40ssc-g all versions","motion_module_fx5-80ssc-g all versions","melsec_iq-l_series_motion_module_ld78g4 all versions","melsec_iq-l_series_motion_module_ld78g16 all versions","motion_control_board_mr-em441g all versions","block-type_remote_module_nz2gn2s1-32d all versions","block-type_remote_module_nz2gn2s1-32t all versions","block-type_remote_module_nz2gn2s1-32te all versions","block-type_remote_module_nz2gn2s1-32dt all versions","block-type_remote_module_nz2gn2s1-32dte all versions","block-type_remote_module_nz2gn2b1-32d all versions","block-type_remote_module_nz2gn2b1-32t all versions","block-type_remote_module_nz2gn2b1-32te all versions","block-type_remote_module_nz2gn2b1-32dt all versions","block-type_remote_module_nz2gn2b1-32dte all versions","block-type_remote_module_nz2gncf1-32d all versions","block-type_remote_module_nz2gncf1-32t all versions","block-type_remote_module_nz2gnce3-32d all versions","block-type_remote_module_nz2gnce3-32dt all versions","block-type_remote_module_nz2gn12a4-16d all versions","block-type_remote_module_nz2gn12a4-16de all versions","block-type_remote_module_nz2gn12a2-16t all versions","block-type_remote_module_nz2gn12a2-16te all versions"],"published":"2026-07-30","updated":"2026-09-18","sourceUpdated":"2026-09-18T00:16:53.720","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-13584","references":[{"url":"https://jvn.jp/vu/JVNVU98879231/","label":"Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-07","label":"Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp"},{"url":"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-005_en.pdf","label":"Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-07-30T12:54:42.601094Z"},"cvssSource":"cna","epss":0.00127,"epssPercentile":0.02716,"ingestedAt":"2026-09-18T00:32:43.468Z","slug":"CVE-2026-13584","body":"## Overview\n\nImproper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board, Block-type remote module, Block-type remote module with safety functions, Analog-Digital converter module, Digital-Analog converter module, CC-Link IE TSN compatible coupler, FPGA module, Tension meter, AC Servo MELSERVO-J5, AC Servo MELSERVO-JET, Liner Track System MTR-S series Linear track control module, Inverter FR-A800/F800/E800 Series, Industrial Robot CR800-D series controller Network Base Card, CC-Link IE TSN expansion unit, CC-Link IE TSN-CC-Link IE Field Network bridge module, CC-Link IE TSN-AnyWireASLINK bridge module, Energy Measuring Unit CC-Link IE TSN Communication Unit, GOT3000 Series, CC-Link IE TSN Communication Unit, Motion Control Software, CC-Link IE TSN Communication Software for Windows, Analysis Support Software MELSOFT VIMA, Master/Local module Designated communication LSI DeviceKit, Remote Station Communication LSI with GbE-PHY, CC-Link IE TSN Master/Local module Designated communication LSI SDK, and Remote station software development kit allows an attacker with access to a CC-Link IE TSN network to tamper with communication data (control input/output values) by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}