Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical DoS Vulnerability (CVE‑2025‑3511) in Mitsubishi Electric Multiple FA Products (Update D)

CISA has warned that CVE‑2025‑3511 allows remote attackers to trigger denial‑of‑service on Mitsubishi Electric CC‑Link IE TSN Remote I/O modules via crafted UDP packets. The flaw threatens operational continuity and requires immediate patching and monitoring to satisfy SOC 2 audit expectations.

LiveThreat™ Intelligence · 📅 August 27, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
cisa.gov

Critical DoS Vulnerability (CVE‑2025‑3511) in Mitsubishi Electric Multiple FA Products (Update D)

What It Is — A remote‑code‑execution flaw in several Mitsubishi Electric CC‑Link IE TSN Remote I/O modules (Update D) that can be triggered by a specially‑crafted UDP packet. Successful exploitation forces a denial‑of‑service, timeout error, or communication delay.

Exploitability — Publicly disclosed in a CISA advisory; no public PoC, but the attack requires only network access to the device’s UDP port, making it readily exploitable in poorly segmented environments. CVSS v3.1 ≈ 7.5 (High).

Affected Products — Mitsubishi Electric CC‑Link IE TSN Remote I/O modules (NZ2GN2S1‑32D, NZ2GN2S1‑32T, NZ2GN2S1‑32TE, NZ2GN2S1‑32DT, NZ2GN2S1‑32DTE, NZ2GN2B1‑32D, NZ2GN2B1‑32T, NZ2GN2B1‑32TE, NZ2GN2B1‑32DT, NZ2GN2B1‑32DTE, NZ2GNCF1‑32D, NZ2GNCF1‑32T, etc.) ≤ v09.

Why It Matters for Compliance & Audit Readiness

  • Control Mapping: The DoS condition directly impacts SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management) controls that require documented, continuous monitoring of critical OT assets.
  • Evidence Collection: Demonstrating that you have automated detection of anomalous UDP traffic and that patches are applied provides concrete audit evidence of “risk mitigation” and “operational resilience.”
  • Enterprise Buyer Expectations: Many industrial‑sector customers now demand proof of SOC 2‑aligned OT security as a prerequisite for contracts; unpatched devices become a red flag in vendor‑risk assessments.

Recommended Actions

  • Apply Mitsubishi’s latest firmware update for all listed modules (v09 or later).
  • Deploy network‑level segmentation and IDS/IPS signatures to detect malformed UDP packets targeting the affected ports.
  • Map the vulnerability to SOC 2 CC6.1 and CC7.1 controls in your compliance framework; capture patch‑status and IDS alerts as continuous evidence.
  • Update your vendor‑risk questionnaire to include OT‑device patch‑management and DoS‑resilience checks.

Source: CISA Advisory – ICSA‑25‑128‑03

📰 Original Source
https://www.cisa.gov/news-events/ics-advisories/icsa-25-128-03 ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →