CVE-2024-49572

7.2

Socomec · DIRIS Digiware M-70

A denial of service and authentication bypass vulnerability exists in the Modbus TCP functionality of the Socomec DIRIS Digiware M-70, allowing unauthenticated attackers to trigger the flaw.

Executive summary

An unauthenticated vulnerability in the Socomec DIRIS Digiware M-70 enables denial of service and credential resets, posing a significant risk to industrial control network availability.

Vulnerability

This vulnerability is caused by missing authentication for critical functions (CWE-306) within the Modbus TCP implementation, where a specially crafted network packet can trigger a denial of service and force the device to revert to default credentials. An unauthenticated attacker can exploit this remotely over the network.

Business impact

The ability for an unauthenticated attacker to remotely disrupt the availability of critical industrial hardware constitutes a high risk to operational continuity. By forcing the device to apply default credentials, the vulnerability further facilitates unauthorized access, potentially leading to the compromise of broader industrial control systems and sensitive operational data. The CVSS score of 7.2 reflects this high impact on system availability and integrity.

Remediation

Immediate Action: Review the official Socomec security advisory and coordinate with your OT/ICS engineering teams to evaluate if the device is currently running version 1.6.9 and if a firmware update is available for deployment.

Proactive Monitoring: Monitor network traffic for unusual Modbus TCP activity directed at the M-70 device, specifically focusing on malformed or high-frequency traffic patterns that may indicate exploitation attempts.

Compensating Controls: Restrict network access to the Modbus TCP interface by placing the device behind a secure gateway or firewall that limits communication to authorized management stations only.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical nature of industrial controllers and the potential for total loss of service, users should prioritize the isolation of affected Socomec devices from public-facing or untrusted networks. Immediate verification of current firmware and consultation with the vendor for patch availability is required to mitigate the risk of unauthorized credential resets and service disruption.

Sources

Originally found and disclosed by Discovered by Kelly Patterson of Cisco Talos., per the CVE Program record.