CVE-2025-54851: Socomec DIRIS Digiware M-70 Unauthenticated Denial of Service Vulnerability

ISGroup Cybersecurity

The Socomec DIRIS Digiware M-70 is a modular energy monitoring device, frequently used in critical infrastructure environments such as data centers, industrial plants, and commercial facilities. These devices provide essential visibility into electrical installations, allowing operators to manage power quality, anticipate failures, and optimize energy consumption. Their function is critical for maintaining operational stability and preventing costly downtime.

This vulnerability represents a significant risk as it allows an unauthenticated attacker with network access to render the device inoperable remotely, causing a complete loss of energy monitoring functionality. The complexity of the attack is low and requires only a single, specially crafted network packet to trigger the denial-of-service condition. This can lead to operational blindness, potentially masking serious electrical faults or overloads that could cause equipment damage or widespread outages.

Although the vulnerability is not present in CISA’s Known Exploited Vulnerabilities (KEV) catalog and there is no evidence of active exploitation, its simplicity makes it an attractive target for threat actors. Any organization relying on this device for power management in sensitive environments should consider it a high-priority threat, especially for devices not isolated from corporate or external networks.

ProductSocomec DIRIS Digiware M-70
Date2025-12-05 00:20:44

Technical Summary

The denial-of-service vulnerability is due to improper input validation during the processing of certain Modbus commands. The root cause appears to be a flaw in the device firmware that does not correctly handle a specific write operation, leading to a system hang or process crash. This vulnerability falls under the category CWE-20: Improper Input Validation.

The attack is carried out by sending a malicious Modbus TCP packet to the device’s management interface on port 503. The technical sequence is as follows:

  1. An unauthenticated attacker creates a “Write Single Register” Modbus TCP request, which corresponds to function code 6.
  2. The request is specifically configured to target register 4352.
  3. The value to be written to this register is set to 1.
  4. Upon receipt and processing of this single packet, the device firmware enters an unstable state and stops functioning, effectively causing a denial-of-service. The device becomes unresponsive and no longer provides monitoring data until a manual reboot.

The vulnerability is confirmed in firmware version 1.6.9. As of this advisory, a patched version has not been specified. An attacker can exploit this vulnerability to disrupt critical monitoring operations, causing significant operational impact without the need for access or credentials.

Recommendations

  • Apply Patches Immediately: Contact the vendor, Socomec, for information on firmware updates that resolve this vulnerability. Organizations should plan for immediate deployment as soon as the patch becomes available.
  • Mitigations:
    • Restrict network access to Modbus TCP port 503 on DIRIS Digiware M-70 devices. Access should be limited to a trusted management subnet or specific authorized IP addresses.
    • Implement strict network segmentation to isolate Industrial Control System (ICS) and Operational Technology (OT) networks from corporate IT networks and external networks.
    • Deploy firewalls or network access control rules to block all unsolicited inbound traffic to the device.

  • Analysis and Monitoring:

    • Monitor network traffic for Modbus TCP packets directed to port 503. In particular, create detection rules for “Write Single Register” commands (function code 6) directed to register 4352.
    • Implement availability monitoring for all DIRIS Digiware M-70 devices to generate alerts in case of unresponsiveness or unexpected reboots.

  • Incident Response:

    • If a device is found to be unresponsive, isolate it immediately from the network to prevent further interaction.
    • Preserve network logs and device logs (if accessible) to identify the source IP address that sent the malicious packet before proceeding with a manual reboot.

  • Defense in Depth:

    • Ensure you have a complete and up-to-date inventory of all OT devices.
    • Regularly review and enforce network segmentation policies between IT and OT environments.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert