Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP Module Improper Resource Shutdown or Release (CVE-2026-1875)

high Tenable OT Security Plugin ID 505912

Synopsis

The remote OT asset is affected by a vulnerability.

Description

Improper Resource Shutdown or Release vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP versions 1.000 and prior allows a remote attacker to cause a denial-of-service (DoS) condition on the products by continuously sending UDP packets to the products. A system reset of the product is required for recovery.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Refer to the vendor advisory.

See Also

https://jvn.jp/vu/JVNVU93286687/

https://www.cisa.gov/news-events/ics-advisories/icsa-26-62-01

http://www.nessus.org/u?249bfcba

Plugin Details

Severity: High

ID: 505912

File Name: tenable_ot_mitsubishi_CVE-2026-1875.nasl

Version: 1.1

Type: Remote

Family: Tenable.ot

Published: 7/31/2026

Updated: 7/31/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.73

CVSS v3

Risk Factor: High

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Vulnerability Information

CPE: cpe:/o:mitsubishielectric:melsec_iq-f_fx5-eip_firmware

Required KB Items: Tenable.ot/Mitsubishi

Patch Publication Date: 3/3/2026

Vulnerability Publication Date: 3/3/2026

Reference Information

CVE: CVE-2026-1875

CWE: 404