← All Advisories

Rapidly Established TCP Connections Trigger an Integer Overflow in Mitsubishi MELSEC FX5-EIP Connection Management, Causing Denial of Service

Last refreshed2026-09-29

Status: NEW  |  Advisory ID: CVE-2026-8805

Key Details

CVECVE-2026-8805
CVSS Score / Version8.7 (High) / CVSS v4.0
Updated2026-06-22
Classified asCWE-190 (Integer Overflow or Wraparound)

What to Know

Integer Overflow or Wraparound vulnerability in the EtherNet/IP function of Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP module FX5-EIP versions 1.000 and prior allows a remote attacker to cause a denial-of-service (DoS) condition in the affected product by rapidly establishing a large number of TCP connections to it, resulting in an inconsistency in the product's internal connection management process and triggering improper memory access.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-8805
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-8805