CVE-2025-55222
8.6Socomec · DIRIS Digiware M-70
A denial of service vulnerability in the Modbus TCP and RTU over TCP functionality of the Socomec DIRIS Digiware M-70 allows unauthenticated attackers to crash the device via crafted packets.
Executive summary
The Socomec DIRIS Digiware M-70 is susceptible to a denial of service attack that can be triggered by an unauthenticated attacker, potentially leading to critical infrastructure disruption.
Vulnerability
This vulnerability, categorized as CWE-306, stems from missing authentication for critical functions within the Modbus interface. An unauthenticated attacker can send a specially crafted network packet to port 503, triggering a denial of service condition on the target device.
Business impact
The vulnerability carries a CVSS score of 8.6, reflecting its high severity due to the potential for total loss of availability of the affected power monitoring unit. Successful exploitation could result in significant operational downtime for industrial or data center power systems, causing loss of visibility and control over critical energy infrastructure.
Remediation
Immediate Action: Restrict network access to the Modbus interface (port 503) to trusted management subnets only, effectively preventing unauthorized access. Contact Socomec support immediately to obtain the latest firmware updates or security patches for version 1.6.9.
Proactive Monitoring: Monitor network traffic for unusual or malformed Modbus RTU over TCP packets directed at port 503. Log and alert on repeated connection attempts from unauthorized IP addresses.
Compensating Controls: Deploy industrial firewalls or deep packet inspection (DPI) solutions capable of validating Modbus protocol traffic to block malformed or unauthorized commands before they reach the device.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical role of the DIRIS Digiware M-70 in power management, this vulnerability poses a severe threat to system availability. Administrators should prioritize network segmentation to isolate the device from untrusted networks while awaiting definitive patching instructions from the vendor. Immediate implementation of access controls is required to mitigate the risk of remote service disruption.
Sources
Originally found and disclosed by Discovered by Kelly Patterson of Cisco Talos., per the CVE Program record.