A vulnerability (CVE-2025-2399) in Mitsubishi Electric CNC Series devices allows remote attackers to trigger a denial-of-service condition via an out-of-bounds read. The flaw is exploited by sending specially crafted packets to TCP port 683. Multiple models across several product series are affected, with vendor fixes available for most.
DoS
4 posts
Mitsubishi Electric CNC Series (Update A) (CVE-2025-2399) Mitsubishi Electric Multiple FA Products (Update D) (CVE-2025-3511) CVE-2025-3511 is a high-severity (CVSS 7.5) denial-of-service vulnerability in the Ethernet function of over 50 Mitsubishi Electric FA product models. A remote, unauthenticated attacker can send a specially crafted UDP packet to cause a DoS condition, timeout error, or communication delay. Most affected products require a system reset for recovery. Firmware updates are available for all affected products.
Release the RAVEN: Destruction and Discipline RAVEN is an open-source offensive security framework targeting Elasticsearch and Kibana. Part 5 of the series demonstrates the tool's destructive capabilities including index deletion, document wiping, mapping corruption, Meow attack simulation, and five denial-of-service modes. All destructive operations are gated behind a triple-confirmation safety system and logged for auditability, with a cleanup module that reverses reversible actions.
CVE-2026-42945: Mitigating a Critical Heap Buffer Overflow Vulnerability in NGINX CVE-2026-42945, dubbed 'NGINX Rift', is a critical heap buffer overflow vulnerability in the NGINX HTTP rewrite module (ngxhttprewrite_module). It allows unauthenticated attackers to cause a Denial of Service (DoS) or potentially achieve Remote Code Execution (RCE) by sending crafted HTTP requests to servers configured with specific rewrite directives containing unnamed PCRE captures and a question mark.