Improper Handling of Length Parameter Inconsistency vulnerability in web server function on Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to delay the processing of the web server function and prevent legitimate users from utilizing the web server function, by sending a specially crafted HTTP request.
History

Tue, 26 Aug 2025 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Mitsubishi Electric
Mitsubishi Electric melsec Iq-f Series
Vendors & Products Mitsubishi Electric
Mitsubishi Electric melsec Iq-f Series

Mon, 25 Aug 2025 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 25 Aug 2025 06:00:00 +0000

Type Values Removed Values Added
Description Improper Handling of Length Parameter Inconsistency vulnerability in web server function on Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to delay the processing of the web server function and prevent legitimate users from utilizing the web server function, by sending a specially crafted HTTP request.
Title Denial-of-Service(DoS) Vulnerability in Web server function on MELSEC iQ-F Series CPU module
Weaknesses CWE-130
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mitsubishi

Published: 2025-08-25T05:55:32.622Z

Updated: 2025-08-26T04:19:57.230Z

Reserved: 2025-06-03T06:22:17.624Z

Link: CVE-2025-5514

cve-icon Vulnrichment

Updated: 2025-08-25T18:01:51.757Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-25T06:15:27.933

Modified: 2025-08-25T20:24:45.327

Link: CVE-2025-5514

cve-icon Redhat

No data.