Denial of Service Vulnerability in Socomec DIRIS Digiware Product
CVE-2024-49572

7.2HIGH

Key Information:

Vendor

Socomec

Vendor
CVE Published:
1 December 2025

What is CVE-2024-49572?

A denial of service vulnerability has been identified in the Modbus TCP functionality of the Socomec DIRIS Digiware M-70 device version 1.6.9. This vulnerability allows an attacker to send specially crafted network packets that can disrupt the normal operation of the device. As a consequence, the device may revert to its default documented credentials, significantly compromising its security. The attack can be executed without authentication, making it critical for users to implement appropriate security measures. For more information, refer to the official documentation and vulnerability reports.

Affected Version(s)

DIRIS Digiware M-70 1.6.9

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Kelly Patterson of Cisco Talos.
.