Denial of Service Vulnerability in Socomec DIRIS Digiware M-70
CVE-2025-54848
7.5HIGH
What is CVE-2025-54848?
A vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of the Socomec DIRIS Digiware M-70 version 1.6.9. Exploitation of this vulnerability allows an attacker to send a specially crafted series of network packets to trigger a denial of service condition. By leveraging the Write Single Register function on Modbus TCP communications to port 502, an attacker can disrupt service. The attack sequence initiates with a configuration message, followed by subsequent commands that finalize a configuration change, subsequently placing the device into a denial-of-service state.
Affected Version(s)
DIRIS Digiware M-70 1.6.9
