CVE-2024-53684

7.5

Socomec · DIRIS Digiware M-70

A cross-site request forgery vulnerability in the Socomec DIRIS Digiware M-70 WEBVIEW-M module allows unauthorized actions via crafted HTTP requests.

Executive summary

A cross-site request forgery vulnerability in the Socomec DIRIS Digiware M-70 power monitoring unit allows an unauthenticated attacker to perform unauthorized actions on the device.

Vulnerability

This is a Cross-Site Request Forgery (CWE-352) flaw within the WEBVIEW-M functionality, which does not adequately validate requests. An unauthenticated attacker can trick a legitimate user into executing unintended actions by hosting a malicious webpage.

Business impact

The exploitation of this vulnerability could lead to unauthorized configuration changes or unauthorized access to the power monitoring unit. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to operational technology environments, potentially resulting in compromised energy monitoring data or unauthorized industrial control system interaction.

Remediation

Immediate Action: Consult the official Socomec security advisory for firmware updates or configuration hardening steps to mitigate CSRF risks.

Proactive Monitoring: Review web server access logs for anomalous requests originating from external sources or unexpected user sessions.

Compensating Controls: Implement network segmentation to restrict access to the device management interface, and utilize browser-based security extensions or WAF rules to block suspicious cross-origin requests.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing the Socomec DIRIS Digiware M-70 should prioritize this issue due to the potential for unauthorized device management. Administrators must monitor the vendor website for firmware patches and restrict access to the device management interface to authorized personnel only until a permanent fix is applied.

Sources

Originally found and disclosed by Discovered by Kelly Patterson of Cisco Talos., per the CVE Program record.