CVE-2025-54849

7.5

Socomec · DIRIS Digiware M-70

A denial of service vulnerability in the Modbus TCP/RTU functionality of the Socomec DIRIS Digiware M-70 allows unauthenticated attackers to disrupt device operations via crafted network requests.

Executive summary

An unauthenticated denial of service vulnerability in the Socomec DIRIS Digiware M-70 allows remote attackers to disrupt industrial monitoring capabilities by sending specifically crafted Modbus messages.

Vulnerability

This flaw is classified as a missing authentication for critical function (CWE-306). An unauthenticated attacker can send a single Modbus TCP message to port 502 using the Write Single Register function code to change the Modbus address, effectively forcing the device into a non-functional state.

Business impact

The successful exploitation of this vulnerability results in a complete loss of availability for the affected power monitoring device. In industrial environments, this disruption can blind operators to critical power metrics, potentially leading to operational inefficiencies or the inability to respond to power-related safety events. With a CVSS score of 7.5, this high-severity flaw poses a significant risk to industrial control systems where continuous uptime is required.

Remediation

Immediate Action: Restrict network access to the Modbus port (TCP 502) to only authorized and trusted management workstations.

Proactive Monitoring: Monitor network traffic for anomalous Modbus function code 6 (Write Single Register) operations targeting register 4352, which is an indicator of exploitation attempts.

Compensating Controls: Implement firewall rules or Industrial Control System (ICS) firewalls to block unauthorized access to the device management interface and Modbus traffic from untrusted network segments.

Exploitation status

Public Exploit Available: No (no confirmed public exploit available in current data).

Analyst recommendation

Given the critical nature of industrial monitoring hardware, administrators must prioritize the network-level isolation of the Socomec DIRIS Digiware M-70. While a vendor patch is currently unavailable, implementing strict access controls on the Modbus TCP port will effectively mitigate the threat posed by this unauthenticated vulnerability. Security teams should ensure that these devices are never exposed to the public internet or untrusted internal networks.

Sources

Originally found and disclosed by Discovered by Kelly Patterson of Cisco Talos., per the CVE Program record.