CVE-2025-20085

7.2

Socomec · DIRIS Digiware M-70

A critical flaw in Socomec DIRIS Digiware M-70 allows unauthenticated attackers to cause a denial of service and force the device to revert to default credentials.

Executive summary

An unauthenticated remote denial of service and credential vulnerability in Socomec DIRIS Digiware M-70 poses a significant risk to industrial network availability and security.

Vulnerability

This vulnerability involves missing authentication for critical functions (CWE-306) within the Modbus RTU over TCP implementation. An unauthenticated attacker can send specially crafted network packets to trigger a denial of service state and force the device to reset to default credentials.

Business impact

The ability for an unauthenticated remote actor to disrupt operational technology services and weaken device security by reverting to default credentials presents a severe threat to business continuity. Given the CVSS score of 7.2, this vulnerability could facilitate unauthorized access to industrial control systems, potentially leading to operational downtime or further lateral movement within the network.

Remediation

Immediate Action: Update the Socomec DIRIS Digiware M-70 firmware to the latest version provided by the vendor to remediate the authentication flaw.

Proactive Monitoring: Monitor network traffic for anomalous Modbus RTU over TCP packets and configure alerts for any unauthorized attempts to access device management interfaces.

Compensating Controls: Isolate affected devices within segmented network environments and employ industrial firewalls to restrict access to Modbus ports to authorized management stations only.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The risk posed by CVE-2025-20085 is substantial due to the potential for remote, unauthenticated disruption of industrial control hardware. Administrators must prioritize applying vendor-supplied firmware updates to the affected DIRIS Digiware M-70 units immediately. If patching is not immediately feasible, network isolation is essential to prevent external access to the vulnerable Modbus interface.

Sources

Originally found and disclosed by Discovered by Kelly Patterson of Cisco Talos., per the CVE Program record.