The Socomec DIRIS Digiware M-70 is an industrial power meter used to monitor electrical installations within critical facilities such as data centers, manufacturing plants, and commercial buildings. These devices are essential for maintaining operational visibility into power quality, energy consumption, and overall system health, directly impacting uptime and energy efficiency.
An unauthenticated attacker can remotely trigger a denial-of-service condition, rendering the device unresponsive and interrupting all monitoring functions. This creates a severe operational blind spot, potentially concealing underlying electrical faults or safety issues that could lead to prolonged service outages, equipment damage, or inefficient energy management.
Although CVE-2025-55221 is not listed in CISA’s KEV (Known Exploited Vulnerabilities) catalog, a public proof-of-concept is available. The low complexity of the attack, combined with the critical function of these devices, represents a significant risk. Any DIRIS Digiware M-70 device with the Modbus TCP port (502/TCP) exposed to untrusted networks is considered highly vulnerable.
| Product | DIRIS Digiware M-70 |
| Date | 2025-12-05 00:37:42 |
Technical Summary
The vulnerability is caused by improper handling of malformed packets within the Modbus TCP service running on port 502. The device’s network stack fails to properly validate or sanitize incoming requests, resulting in a denial-of-service condition when a specially crafted packet is processed. This most likely triggers an unhandled exception or resource exhaustion that causes the main process to crash or hang in an infinite loop.
The attack unfolds as follows:
- An unauthenticated attacker establishes a TCP connection to port 502 on a vulnerable Socomec DIRIS Digiware M-70 device.
- The attacker sends a single, specially crafted Modbus TCP packet that deviates from the expected protocol structure.
- The device firmware attempts to parse this anomalous packet, triggering an error condition from which it cannot recover.
- The device becomes completely unresponsive to any further network requests, and its power monitoring capabilities cease until it is manually restarted.
Affected Versions:
- Socomec DIRIS Digiware M-70 firmware version 1.6.9 and likely previous versions.
A patch has been released by the vendor. Users should consult the manufacturer’s official advisories to identify the correct firmware version. An attacker does not require authentication and only needs network access to the Modbus TCP port to execute the attack and compromise critical energy monitoring operations.
Recommendations
- Apply patches immediately: Organizations must immediately identify all vulnerable Socomec DIRIS Digiware M-70 devices and update them to the latest stable firmware version provided by the manufacturer.
- Mitigations:
- Restrict network access to the Modbus TCP service on port 502. Use strict firewall rules to ensure that only trusted management stations and authorized industrial control systems can communicate with the device.
- If possible, implement network segmentation to isolate ICS (Industrial Control Systems) and OT (Operational Technology) systems from corporate IT networks and the internet.
- Detection and monitoring:
- Monitor network traffic for unusual or malformed Modbus TCP packets destined for port 502.
- Configure network monitoring systems and device logs to generate alerts in the event of unexpected restarts or periods of unresponsiveness from DIRIS Digiware M-70 devices.
- Analyze firewall and IDS/IPS logs to detect scanning activity or connection attempts to port 502 from untrusted IP addresses.
- Incident response:
- If a compromise is suspected or a device becomes unresponsive, isolate it from the network immediately to prevent further disruption.
- Retain logs and network captures from the time of the incident to facilitate forensic analysis.
- Perform a controlled manual restart of the device to restore monitoring functionality after isolation.
- Defense in depth:
- Maintain a comprehensive inventory of all OT devices, including their firmware versions, to quickly identify vulnerable systems.
- Verify that device configurations are regularly backed up to facilitate rapid recovery.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
