---
id: CVE-2026-13584
title: >-
  Improper Enforcement of Message Integrity During Transmission in a
  Communication Channel vulnerability in Mitsubishi Electric MELSEC MX
  Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module,
  CC-Link IE TSN interface…
summary: >-
  Improper Enforcement of Message Integrity During Transmission in a
  Communication Channel vulnerability in Mitsubishi Electric MELSEC MX
  Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module,
  CC-Link IE TSN interface…
severity: high
cvss: 7.1
cvssVector: 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'
cwe:
  - CWE-924
vendor: Mitsubishi Electric Corporation
product: MELSEC MX Controller MX-R model MXR300-16
affected:
  - melsec_mx_controller_mx-r_model_mxr300-16 all versions
  - melsec_mx_controller_mx-r_model_mxr300-32 all versions
  - melsec_mx_controller_mx-r_model_mxr300-64 all versions
  - melsec_mx_controller_mx-r_model_mxr500-128 all versions
  - melsec_mx_controller_mx-r_model_mxr500-256 all versions
  - melsec_mx_controller_mx-f_model_mxf100-8-n32 all versions
  - melsec_mx_controller_mx-f_model_mxf100-8-p32 all versions
  - melsec_mx_controller_mx-f_model_mxf100-16-n32 all versions
  - melsec_mx_controller_mx-f_model_mxf100-16-p32 all versions
  - melsec_mx_controller_mx-f_model_mxf100s-n32 all versions
  - melsec_mx_controller_mx-f_model_mxf100s-p32 all versions
  - melsec_mx_controller_mx-f_model_mxf100s-8-n32 all versions
  - melsec_mx_controller_mx-f_model_mxf100s-8-p32 all versions
  - melsec_mx_controller_mx-f_model_mxf100s-16-n32 all versions
  - melsec_mx_controller_mx-f_model_mxf100s-16-p32 all versions
  - master_local_module_rj71gn11-t2 all versions
  - master_local_module_rj71gn11-sx all versions
  - master_local_module_rj71gn11-eip all versions
  - master_local_module_fx5-cclgn-ms all versions
  - cc-link_ie_tsn_interface_board_nz81gn11-sx all versions
  - cc-link_ie_tsn_interface_board_nz81gn11-t2 all versions
  - motion_module_rd78g4 all versions
  - motion_module_rd78g8 all versions
  - motion_module_rd78g16 all versions
  - motion_module_rd78g64 all versions
  - motion_module_rd78ghv all versions
  - motion_module_rd78ghw all versions
  - motion_module_fx5-40ssc-g all versions
  - motion_module_fx5-80ssc-g all versions
  - melsec_iq-l_series_motion_module_ld78g4 all versions
  - melsec_iq-l_series_motion_module_ld78g16 all versions
  - motion_control_board_mr-em441g all versions
  - block-type_remote_module_nz2gn2s1-32d all versions
  - block-type_remote_module_nz2gn2s1-32t all versions
  - block-type_remote_module_nz2gn2s1-32te all versions
  - block-type_remote_module_nz2gn2s1-32dt all versions
  - block-type_remote_module_nz2gn2s1-32dte all versions
  - block-type_remote_module_nz2gn2b1-32d all versions
  - block-type_remote_module_nz2gn2b1-32t all versions
  - block-type_remote_module_nz2gn2b1-32te all versions
  - block-type_remote_module_nz2gn2b1-32dt all versions
  - block-type_remote_module_nz2gn2b1-32dte all versions
  - block-type_remote_module_nz2gncf1-32d all versions
  - block-type_remote_module_nz2gncf1-32t all versions
  - block-type_remote_module_nz2gnce3-32d all versions
  - block-type_remote_module_nz2gnce3-32dt all versions
  - block-type_remote_module_nz2gn12a4-16d all versions
  - block-type_remote_module_nz2gn12a4-16de all versions
  - block-type_remote_module_nz2gn12a2-16t all versions
  - block-type_remote_module_nz2gn12a2-16te all versions
published: '2026-07-30'
updated: '2026-09-18'
sourceUpdated: '2026-09-18T00:16:53.720'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-13584'
references:
  - url: 'https://jvn.jp/vu/JVNVU98879231/'
    label: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
  - url: 'https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-07'
    label: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
  - url: 'https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-005_en.pdf'
    label: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-07-30T12:54:42.601094Z'
cvssSource: cna
epss: 0.00191
epssPercentile: 0.07791
ingestedAt: '2026-09-18T00:32:43.468Z'
---

## Overview

Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board, Block-type remote module, Block-type remote module with safety functions, Analog-Digital converter module, Digital-Analog converter module, CC-Link IE TSN compatible coupler, FPGA module, Tension meter, AC Servo MELSERVO-J5, AC Servo MELSERVO-JET, Liner Track System MTR-S series Linear track control module, Inverter FR-A800/F800/E800 Series, Industrial Robot CR800-D series controller Network Base Card, CC-Link IE TSN expansion unit, CC-Link IE TSN-CC-Link IE Field Network bridge module, CC-Link IE TSN-AnyWireASLINK bridge module, Energy Measuring Unit CC-Link IE TSN Communication Unit, GOT3000 Series, CC-Link IE TSN Communication Unit, Motion Control Software, CC-Link IE TSN Communication Software for Windows, Analysis Support Software MELSOFT VIMA, Master/Local module Designated communication LSI DeviceKit, Remote Station Communication LSI with GbE-PHY, CC-Link IE TSN Master/Local module Designated communication LSI SDK, and Remote station software development kit allows an attacker with access to a CC-Link IE TSN network to tamper with communication data (control input/output values) by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a denial-of-service (DoS) condition in the affected product by interfering with its control function or causing it to operate incorrectly.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
