The Socomec DIRIS Digiware M-70 is a critical infrastructure component used for advanced energy monitoring and measurement in industrial environments, data centers, and commercial facilities. It functions as a central gateway, aggregating data from multiple measurement modules to provide real-time visibility into power quality and consumption. Its proper operation is essential for OT (operational technology) visibility, preventive maintenance, and energy efficiency management.
A complete denial-of-service condition can be triggered by an unauthenticated remote attacker. This vulnerability is particularly severe as it requires no user interaction or prior access. The primary risk concerns any DIRIS Digiware M-70 gateway with the Modbus TCP port (502) exposed to untrusted networks. While there are currently no confirmed reports of active exploitation, a simple public exploit method exists, increasing the likelihood that malicious actors may target it in the future to compromise the operation of critical infrastructure.
| Product | Socomec DIRIS Digiware M-70 |
| Date | 2025-12-05 12:34:46 |
Technical Summary
The vulnerability is caused by inadequate access control on system configuration registers accessible via the Modbus TCP protocol. An unauthenticated attacker can exploit the ‘Write Single Register’ (function code 6) command to modify specific memory areas that regulate the device’s operational state, ultimately forcing it into a non-functional mode that persists until a manual reboot.
The attack chain unfolds as follows:
- The attacker establishes a network connection with the target device on TCP port 502.
- The attacker sends a specially crafted Modbus packet with function code 6 to write a specific value to register 58112.
- A second malicious write operation is performed on register 29440.
- A final write operation to register 57856 applies the malicious configuration changes, triggering the denial-of-service condition.
The device immediately ceases normal operations, including data acquisition and communication, effectively becoming unresponsive. Organizations are advised to consult Socomec for guidance on vulnerable and updated firmware versions.
Recommendations
- Apply patches immediately: Contact the vendor, Socomec, to obtain and install the latest firmware updates on all DIRIS Digiware M-70 devices.
- Mitigations:
- Implement strict network segmentation to isolate the M-70 gateway and other OT devices from the corporate IT network and the Internet.
- Use a firewall to restrict access to TCP port 502 exclusively to trusted IP addresses and authorized engineering workstations or SCADA systems. Deny all traffic by default.
- Hunting & Monitoring:
- Monitor network traffic to detect any unauthorized external or internal systems attempting to communicate with the DIRIS Digiware M-70 on TCP port 502.
- Create detection rules in your SIEM or network monitoring solution to generate alerts on the rapid sequence of Modbus ‘Write Single Register’ (function code 6) requests directed at registers 58112, 29440, and 57856.
- Incident Management:
- If a device becomes unresponsive, immediately implement firewall rules to block the source IP address of the suspected attack.
- Isolate the affected device from the network to prevent lateral movement or further impact.
- Perform a manual power cycle to restore the device’s operational state and apply patches before reconnecting it to the network.
- Defense in Depth:
- Regularly audit firewall rules and network access controls for critical OT infrastructure.
- Ensure that backup and recovery procedures are in place for critical monitoring systems.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
