Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)
CISA updated its CC-Link IE TSN advisory: segment-attached attackers can tamper with Mitsubishi Electric control data and trigger denial of service conditions.
CISA updated its advisory (ICSA-26-211-07 Update A) on a CWE-924 improper enforcement of message integrity flaw in the Mitsubishi Electric CC-Link IE TSN communication protocol. An attacker on the same network segment can send specially crafted packets under specific timing conditions to tamper with control input and output values, causing incorrect operation or denial of service in affected products. Affected products span numerous models, including MELSEC MX controllers, RJ71GN11 modules, motion modules (RD78G/LD78G), FX5 units, and NZ2GN block-type remote modules.