Mitsubishi Electric MELSOFT Update Manager SW1DND-UDM-M
Act NowCVSS 8.8ICS-CERT ICSA-26-181-01Jun 30, 2026
Mitsubishi ElectricEnergy
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
MELSOFT Update Manager SW1DND-UDM-M versions 1.000A through 1.014Q contain multiple vulnerabilities (CWE-122 buffer overflow, CWE-476 NULL pointer dereference, CWE-59 improper link resolution, CWE-22 path traversal) in the bundled 7-Zip decompression component. A local attacker can exploit these by crafting a malicious archive file. Successful exploitation allows arbitrary code execution, information destruction, or denial of service on the affected PC.
What this means
What could happen
A local attacker with user-level credentials on the PC running MELSOFT Update Manager could execute arbitrary code, delete or modify critical data, or crash the application by decompressing a malicious archive file. This could disrupt PLC/controller update processes and potentially compromise the ability to manage industrial equipment.
Who's at risk
Energy sector operators managing PLCs and industrial controllers via Mitsubishi Electric systems should care about this. Specifically, any operator or engineer using MELSOFT Update Manager on a networked PC to deploy firmware updates to Mitsubishi electric drives, programmable logic controllers (PLCs), or other factory automation equipment is at risk if that PC is accessible to local users or remote attackers.
How it could be exploited
An attacker with local access to the machine (or ability to deliver a file to a local user) crafts a malicious compressed archive designed to exploit the 7-Zip component bundled with MELSOFT Update Manager. When the user decompresses the archive through the application, the attacker's code executes with the privileges of that user, allowing tampering with update files or system data.
Prerequisites
- Local user account on the PC running MELSOFT Update Manager
- Ability to place or trick a user into opening a specially crafted archive file
- MELSOFT Update Manager version 1.000A through 1.014Q running on the system
No authentication required for local exploitLow attack complexityAffects software update process for critical industrial equipmentHigh EPSS score (27%)
Exploitability
Likely to be exploited — EPSS score 27.0%
Public Proof-of-Concept (PoC) on GitHub (8 repositories)
Affected products (1)
ProductAffected VersionsFix Status
MELSOFT Update Manager SW1DND-UDM-M: >=1.000A|<=1.014Q≥ 1.000A|≤ 1.014QFix available
Remediation & Mitigation
0/4
Do now
0/2WORKAROUNDRestrict the MELSOFT Update Manager PC to operation within a local area network only and block remote login attempts from untrusted networks and users
HARDENINGDeploy firewall rules or VPN to allow only trusted users to remote login to the MELSOFT Update Manager PC if internet access is required
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate MELSOFT Update Manager SW1DND-UDM-M to version 1.015R or later
Long-term hardening
0/1HARDENINGRestrict physical access to the PC running MELSOFT Update Manager and the network ports it connects to
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/30acf0a3-3f71-46ba-8d51-b359d2d95be0Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.