Critical DoS Vulnerability (CVE‑2025‑3511) in Mitsubishi Electric Multiple FA Products (Update D)
What It Is — A remote‑code‑execution flaw in several Mitsubishi Electric CC‑Link IE TSN Remote I/O modules (Update D) that can be triggered by a specially‑crafted UDP packet. Successful exploitation forces a denial‑of‑service, timeout error, or communication delay.
Exploitability — Publicly disclosed in a CISA advisory; no public PoC, but the attack requires only network access to the device’s UDP port, making it readily exploitable in poorly segmented environments. CVSS v3.1 ≈ 7.5 (High).
Affected Products — Mitsubishi Electric CC‑Link IE TSN Remote I/O modules (NZ2GN2S1‑32D, NZ2GN2S1‑32T, NZ2GN2S1‑32TE, NZ2GN2S1‑32DT, NZ2GN2S1‑32DTE, NZ2GN2B1‑32D, NZ2GN2B1‑32T, NZ2GN2B1‑32TE, NZ2GN2B1‑32DT, NZ2GN2B1‑32DTE, NZ2GNCF1‑32D, NZ2GNCF1‑32T, etc.) ≤ v09.
Why It Matters for Compliance & Audit Readiness
- Control Mapping: The DoS condition directly impacts SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management) controls that require documented, continuous monitoring of critical OT assets.
- Evidence Collection: Demonstrating that you have automated detection of anomalous UDP traffic and that patches are applied provides concrete audit evidence of “risk mitigation” and “operational resilience.”
- Enterprise Buyer Expectations: Many industrial‑sector customers now demand proof of SOC 2‑aligned OT security as a prerequisite for contracts; unpatched devices become a red flag in vendor‑risk assessments.
Recommended Actions
- Apply Mitsubishi’s latest firmware update for all listed modules (v09 or later).
- Deploy network‑level segmentation and IDS/IPS signatures to detect malformed UDP packets targeting the affected ports.
- Map the vulnerability to SOC 2 CC6.1 and CC7.1 controls in your compliance framework; capture patch‑status and IDS alerts as continuous evidence.
- Update your vendor‑risk questionnaire to include OT‑device patch‑management and DoS‑resilience checks.
Source: CISA Advisory – ICSA‑25‑128‑03