CVE-2025-54850

7.5

Socomec · DIRIS Digiware M-70

A denial of service vulnerability in Socomec DIRIS Digiware M-70 allows unauthenticated attackers to disrupt device availability via crafted Modbus TCP/RTU network requests.

Executive summary

A critical denial of service vulnerability in the Socomec DIRIS Digiware M-70, triggered by unauthenticated network traffic, poses a significant risk to operational availability.

Vulnerability

The device suffers from a missing authentication for critical function flaw, allowing an unauthenticated remote attacker to send a specific sequence of Modbus RTU over TCP packets to port 503. By executing a series of Write Single Register commands, the attacker can force a configuration change that renders the device unresponsive.

Business impact

The successful exploitation of this vulnerability results in a complete denial of service for the affected power monitoring device. Given the CVSS score of 7.5, this high severity flaw could lead to significant operational disruption in industrial or data center environments where these units are deployed. Loss of monitoring capabilities can impede incident response and prevent the oversight of critical power infrastructure.

Remediation

Immediate Action: Restrict network access to port 503 to trusted management segments only and contact the vendor for the latest firmware update addressing this specific flaw.

Proactive Monitoring: Monitor network traffic directed at port 503 for unusual sequences of Modbus function code 6 (Write Single Register) targeting registers 58112, 29440, and 57856.

Compensating Controls: Implement strict firewall rules to ensure that only authorized Modbus masters can communicate with the DIRIS Digiware M-70, effectively isolating the device from untrusted networks.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The vulnerability represents a significant risk to the availability of industrial control equipment. Security teams should prioritize the isolation of affected devices from public or untrusted network segments immediately. Once the vendor releases the necessary firmware update, it should be deployed as part of the next scheduled maintenance window to fully remediate the underlying authentication oversight.

Sources

Originally found and disclosed by Discovered by Kelly Patterson of Cisco Talos., per the CVE Program record.