PT-2025-48480 · Socomec · Diris Digiware M-70

Kelly Patterson

·

Published

2025-08-21

·

Updated

2025-12-05

·

CVE-2025-54851

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Socomec DIRIS Digiware M-70 version 1.6.9
Description A denial of service condition can occur due to specially crafted network requests targeting the Modbus TCP and Modbus RTU over TCP functionality. An attacker can trigger this by sending unauthenticated packets. Specifically, sending a Modbus TCP message to port 503 using the Write Single Register function code (6) to write the value 1 to register 4352 changes the Modbus address to 15, resulting in a denial-of-service state.
Recommendations For Socomec DIRIS Digiware M-70 version 1.6.9, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Missing Authentication

Weakness Enumeration

Related Identifiers

BDU:2025-15278
CVE-2025-54851

Affected Products

Diris Digiware M-70