Machine-generated analysis · WAYSCloud LLM
The advisory lists multiple Mitsubishi Electric CNC models (Update A) as vulnerable to CVE-2025-2399. Exploitation may cause an out-of-bounds read leading to denial-of-service.
Context
The affected product is Mitsubishi Electric CNC Series (Update A), including models such as M800VW, M800VS, M80V, M80VW, M800W, and others. The advisory states that an improper validation vulnerability (CVE-2025-2399) could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition. The advisory notes the products are deployed worldwide in the critical manufacturing sector.
Operator considerations
Check: Verify whether any listed CNC models are present in your environment.
Isolate: Consider segmenting CNC control networks from untrusted traffic.
Log: Monitor system logs for unexpected crashes or denial-of-service events.
Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products.
The following versions of Mitsubishi Electric CNC Series (Update A) are affected:
Mitsubishi Electric M800VW (BND-2051W000)
Read the full advisory on CISA →