CC-Link IE TSN CVE-2026-13584: OT Protocol Vulnerability Enabling Control I/O Value Tampering from Adjacent Networks
CC-Link IE TSN CVE-2026-13584: OT Protocol Vulnerability Enabling Control I/O Value Tampering from Adjacent Networks 1. Basic Information Article Name: JVNVU#98879231: Incomplete Integrity Verification in
CC-Link IE TSN CVE-2026-13584: OT Protocol Vulnerability Enabling Control I/O Value Tampering from Adjacent Networks
1. Basic Information
- Article Name: JVNVU#98879231: Incomplete Integrity Verification in CC-Link IE TSN Communication Protocol for Multiple Mitsubishi Electric Products
- Publisher: JVN
- Publication Date: 2026-08-03
- Severity: High
- Original Source: https://jvn.jp/vu/JVNVU98879231/index.html
- Related Sources: Mitsubishi Electric PSIRT 2026-005, CISA ICSA-26-211-07
- Related Entities: CVE-2026-13584, CWE-924, CC-Link IE TSN, MELSEC MX, MELSERVO, GOT3000, Industrial Robots and 35 other categories (all versions)
- CVSS v4.0: 7.1 (AV:A/AC:L/AT:N/PR:N/UI:N/VI:H/VA:L)
2. Executive Summary
A protocol-level vulnerability in CC-Link IE TSN allows an unauthenticated attacker with physical or adjacent network access to send crafted packets at specific timings. This can tamper with control input/output values, causing malfunctions, control interference, or DoS.
3. Attack Flow
- The attacker reaches the CC-Link IE TSN segment from a factory network, maintenance port, or compromised engineering workstation.
- The attacker observes or estimates network traffic and the control cycle/timing.
- The attacker exploits the lack of proper message integrity enforcement to inject crafted packets at a specific timing.
- The target device processes the packets as valid messages, and the control I/O values are altered.
- Actuators, servos, robots, or remote I/O devices malfunction, suffer control interference, or stop.
4. Attacker Position and Execution Points
- The attacker needs adjacent access to CC-Link IE TSN, which does not always mean direct access from the Internet.
- Execution points include unauthorized connected terminals, maintenance PCs, compromised OT/IT bridges, and open Ethernet ports.
- The impact spreads beyond controllers to servos, robots, inverters, HMIs, remote I/O, and industrial PCs.
5. Visibility for Victims and Administrators
- Operators see sensor/actuator value mismatches, unexpected movements, interlocks, or device timeouts/stops.
- Network administrators see regular traffic within the segment, making it hard to judge legitimacy based only on source MAC/IP.
- The key indicator is that process values change without any engineering changes or audits.
6. Success and Failure Conditions
Success Conditions
- The attacker achieves physical or logical access to the CC-Link IE TSN segment.
- The target product uses the affected protocol, and the attacker matches the packet timing.
- Port security, network segmentation, and anomaly detection are insufficient.
Failure Conditions
- Physical control of cabinets, rooms, and Ethernet ports.
- Isolation of trusted networks and blocking communication with untrusted hosts using firewalls/ACLs.
- Use of network admission control, fixed switch ports, OT IDS, and process safety controls to block abnormal packets and values.
7. What Happens on Success
- Tampering with control I/O values, device control interference, malfunctions, or DoS.
- Potential physical impact on manufacturing quality, safety, and equipment availability.
- Cross-cutting risk across many products and all versions due to shared protocol weaknesses.
8. Observable Logs
- Email: Not applicable.
- Proxy/SWG/DNS: Usually not observed as traffic remains within the local OT segment.
- Endpoint/EDR: Packet crafting tools on engineering workstations, NIC promiscuous mode, unknown USB/network adapters. Specialized devices often lack EDR support.
- Identity/IdP: Network access/VPN/NAC authentication and maintenance account usage. Protocol packets themselves are unauthenticated.
- SaaS/Cloud: Only when remote maintenance/ZTNA audits are present.
- Network: Unknown MAC addresses on SPAN/TAP, duplicate/abnormal sequences and timings, unexpected I/O writes, broadcast/multicast patterns, link up/down events, and port moves.
- Process/Safety: Differences between commanded and actual values in PLCs/HMIs/alarm historians, discrepancies with recipe/change management, and activation of safety relays/interlocks.
9. Attack Success Determination
- Contact Only: Segment connection, scanning, or traffic observation.
- User Interaction: None required.
- Initial Execution: Confirmation of crafted packet transmission via packet capture.
- Malware or Successful Authentication: Not applicable. Acceptance of protocol messages marks the success point.
- Information Theft/Session Compromise: Not the primary goal of this vulnerability.
- Subsequent Compromise Confirmation: I/O value tampering, malfunctions, or DoS aligning with packet timestamps.
10. Investigation Playbook
- Trigger: Unexplained I/O changes, device stops, unknown MAC addresses, or packet anomalies outside of maintenance hours.
- Initial Check: Prioritize safety, coordinate with operators to stabilize the process state. Preserve packet captures, switch CAM/port data, and alarm/historian timestamps.
- Endpoints: Check engineering/maintenance PCs, USBs, tools, accounts, and EDR on the same segment.
- Authentication/Cloud: Cross-reference VPN, ZTNA, NAC, and remote maintenance sessions.
- Subsequent Actions: Check the affected 35 product groups across the same segment, bridges, and redundant lines.
- Containment: Isolate unauthorized ports/hosts, separate cells/zones, enable manual/local safe modes, and verify configurations, firmware, and process values.
- Determination Categories: Adjacent Access / Packet Injection Suspected / Malformed Packet Confirmed / I/O Integrity Loss / Physical Impact.
11. Defense and Detection Ideas
- Single Event: Unregistered MAC addresses, port link-ups outside of maintenance, unexpected I/O writes.
- Time-Series Correlation: Port connection -> Traffic observation -> Specific timing packet -> I/O value change -> Alarm/interlock.
- Hunting: Asset inventory check and vulnerable version confirmation across all devices, unmanaged switches/bridges, IT-OT dual-homed hosts, and portable engineering PCs.
- Log Shortages: OT packet captures, switch port audits, time synchronization, historians, and device protocol logs.
- Priority Measures: Physical ports/cabinets, zones/conduits, NAC/ACLs, OT IDS, and independent safety interlocks.
12. Facts / Inference / Hypothesis
Facts
- The message integrity enforcement flaw was published as CVE-2026-13584/CWE-924.
- Adjacent access, low complexity, and zero credentials/user interaction allow control I/O value tampering and DoS.
- Mitsubishi Electric lists all versions across 35 product categories as affected and advises physical/network mitigations rather than patches.
Inference
- Pure IT logs struggle to capture this; time-series correlation of packets, switches, historians, and safety alarms is necessary.
- Because of shared protocol implementations, the same attack primitives can spread to different devices on the same segment.
Hypothesis
- Mixing malicious traffic with regular maintenance traffic from a compromised engineering workstation makes detection harder than using an external terminal.
13. MITRE ATT&CK Mapping
Mapped primarily to ICS ATT&CK.
- T0842 Network Sniffing (Medium, if observation is used to determine timing)
- T0836 Modify Parameter (High)
- T0855 Unauthorized Command Message (High)
- T0813 Denial of Control / T0826 Loss of Availability (High)
- T0827 Loss of Control / T0831 Manipulation of Control (Medium to High)
14. Unknowns and Additional Investigations
- Packet fields, timing windows, reproducibility, and device-specific behaviors.
- Vendor plans for protocol/firmware fixes.
- Mitigation effects in safety-certified configurations.
- Evidence of active exploitation or global incidents.
- Impact on third-party CC-Link IE TSN implementations.
15. Impact on SOCs and Organizations
Factory automation products and CC-Link IE TSN are widely used in global industrial environments. Organizations must audit segments, target model numbers, maintenance ports, remote access points, and dual-homed endpoints, going beyond simply checking for patches. SOCs and plant maintenance teams should establish joint decision-making criteria that factor in safety, quality, and operational impacts rather than relying solely on standard IT incident severity levels.
16. Summary by Role
- For SOCs: Correlate unknown MACs/ports and packet anomalies with historian I/O changes and alarms, assuming EDR is not present.
- For Administrators: Assume all versions are affected, and implement physical access controls, cabinet/port locks, zone separation, ACLs/NAC, and OT IDS.
- For Users: Do not dismiss unexplained display values, malfunctions, or stops as simple equipment failures. Record timestamps and report them immediately to maintenance teams or SOCs.
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.