Denial of Service Vulnerability in Socomec DIRIS Digiware M-70
CVE-2025-54849
7.5HIGH
What is CVE-2025-54849?
A denial of service vulnerability impacts the Modbus TCP and Modbus RTU over TCP functionality of the Socomec DIRIS Digiware M-70. Specifically, an attacker can exploit this vulnerability by sending a sequence of unauthenticated packets. The exploitation involves sending a single Modbus TCP message to port 502 using the Write Single Register function code (6), which, if manipulated to write the value 1 to register 4352, reconfigures the Modbus address. Once this action is completed, the device enters a denial-of-service state, rendering it unresponsive. This vulnerability poses significant risks to network availability and requires urgent attention to prevent unauthorized access and mitigate potential attacks.
Affected Version(s)
DIRIS Digiware M-70 1.6.9
