CVE-2026-8805 Details
Description
Integer Overflow or Wraparound vulnerability in the EtherNet/IP function of Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP module FX5-EIP versions 1.000 and prior allows a remote attacker to cause a denial-of-service (DoS) condition in the affected product by rapidly establishing a large number of TCP connections to it, resulting in an inconsistency in the product's internal connection management process and triggering improper memory access.
A denial-of-service vulnerability has been identified in the Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP module, all versions through 1.000. This vulnerability arises from an integer overflow or wraparound issue, allowing remote attackers to disrupt service by rapidly establishing numerous TCP connections. This influx of connections creates a mismatch in the module's internal connection management, leading to improper memory access and causing the product to enter a DoS state.
Users are advised to update to version 1.001 or later. For the update procedure, refer to the MELSEC iQ-F FX5 User’s Manual (Application). Additionally, Mitsubishi Electric recommends using firewalls or VPNs to prevent unauthorized access, blocking access from untrusted networks, using the IP filter function to block untrusted hosts, restricting physical access to the affected product and connected devices, and installing anti-virus software on PCs that can access the product.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 19, 2026CISA-ADP
Assessed Jun 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/vu/JVNVU97140216/ | [email protected] | AdvisoryBundleRemedy |
| https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-05 | [email protected] | AdvisoryVendor |
| https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-002_en.pdf | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-190 | Integer Overflow or Wraparound | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Mitsubishi Electric MELSEC iQ-F FX5-EIP | <= 1.000 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 22, 2026 | CVE Modified | CISA-ADP |
| Jun 19, 2026 | New CVE Received | [email protected] |
Volerion