CVE Explorer
CVE-2026-8805
Integer Overflow or Wraparound vulnerability in the EtherNet/IP function of Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP module FX5-EIP versions 1.000 and prior allows a remote attacker to cause a denial-of-service (DoS) condition in the affected product by rapidly establishing a large number of TCP connections to it, resulting in an inconsistency in the product's internal connection management process and triggering improper memory access.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP","vendor":"Mitsubishi Electric Corporation","versions":[{"status":"affected","version":"versions 1.000 and prior"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:8442a15b5583ac200d61beb14c1e565efddc4c84b0d5669e5dd689cffdf19649 · sha256:97b5c9a32b0b0614… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:8442a15b5583ac200d61beb14c1e565efddc4c84b0d5669e5dd689cffdf19649 · sha256:97b5c9a32b0b0614… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-190","description":"CWE-190 Integer Overflow or Wraparound","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:8442a15b5583ac200d61beb14c1e565efddc4c84b0d5669e5dd689cffdf19649 · sha256:97b5c9a32b0b0614… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"tags":["government-resource"],"url":"https://jvn.jp/vu/JVNVU97140216/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8442a15b5583ac200d61beb14c1e565efddc4c84b0d5669e5dd689cffdf19649 · sha256:97b5c9a32b0b0614… · /containers/cna/references/1
{"tags":["government-resource"],"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-169-05"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8442a15b5583ac200d61beb14c1e565efddc4c84b0d5669e5dd689cffdf19649 · sha256:97b5c9a32b0b0614… · /containers/cna/references/2
{"tags":["vendor-advisory"],"url":"https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2026-002_en.pdf"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:8442a15b5583ac200d61beb14c1e565efddc4c84b0d5669e5dd689cffdf19649 · sha256:97b5c9a32b0b0614… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.