CVE-2025-55222: Denial of Service Vulnerability in Modbus Service of Socomec DIRIS Digiware M-70

ISGroup Cybersecurity

The Socomec DIRIS Digiware M-70 is a modular gateway for energy and electrical monitoring systems, often used in critical environments such as data centers, industrial plants, and commercial buildings. These devices provide essential visibility into the status and performance of electrical infrastructure.

A high-severity vulnerability allows a remote, unauthenticated attacker to trigger a complete denial of service. A successful attack renders the M-70 gateway non-operational, preventing operators from accessing real-time power data and control functions. This represents a significant operational risk, as the loss of monitoring can delay the response to critical power events, potentially leading to equipment damage or operational outages.

Any organization using these devices with the Modbus service accessible on TCP port 503 from untrusted networks is at high risk of disruption. While a public proof-of-concept exploit exists, there are currently no reports of active exploitation of the vulnerability. This vulnerability is not listed in CISA’s KEV (Known Exploited Vulnerabilities) catalog.

ProductSocomec DIRIS Digiware M-70
Date2025-12-05 00:38:27

Technical Summary

The vulnerability exists in the Modbus TCP and Modbus RTU services listening on TCP port 503 of the Socomec DIRIS Digiware M-70 gateway. The root cause is improper handling of specially crafted Modbus packets, corresponding to CWE-20: Improper Input Validation. The device firmware fails to correctly interpret or validate certain malformed requests.

The attack chain is as follows:

  1. A remote, unauthenticated attacker crafts a specific, malformed Modbus packet.
  2. The packet is sent to the exposed TCP port 503 of a vulnerable M-70 gateway.
  3. The Modbus service attempts to process the invalid packet, causing an unhandled exception or error state that results in the service crashing or the device exhausting its resources.
  4. This causes a complete denial of service, where the gateway stops all monitoring and communication functions. The device becomes unresponsive to all legitimate network requests and requires a manual power cycle to restore functionality.

An attacker with network access to the Modbus port can repeatedly disrupt critical monitoring functions at will. Users should consult the vendor’s official advisories for information on affected and patched firmware versions.

Recommendations

  • Update Immediately: Consult Socomec’s official advisories for firmware updates that resolve CVE-2025-55222 and apply them as soon as possible.

  • Mitigations:

    • Restrict Network Access: Ensure the DIRIS Digiware M-70 gateway is not exposed to the Internet. Use firewalls or Access Control Lists (ACLs) to strictly limit access to TCP port 503 to trusted management stations and authorized devices only.
    • Network Segmentation: Isolate Industrial Control Systems (ICS) and Operational Technology (OT) networks from corporate IT networks to prevent unauthorized access and reduce the attack surface.

  • Hunting & Monitoring:

    • Monitor network traffic and firewall logs to detect unauthorized connection attempts or scanning activity directed at TCP port 503 on sensitive devices.
    • Implement uptime monitoring and create alerts for unexpected reboots or periods of unresponsiveness from the M-70 gateway, as these are key indicators of a successful DoS attack.

  • Incident Response:

    • If a device becomes unresponsive, immediately implement network ACLs to isolate it from the suspected source of the attack.
    • Retain logs from upstream network devices for forensic analysis. A manual power cycle of the device will be required to restore functionality.

  • Defense in Depth:

    • Maintain a comprehensive inventory of all OT assets and their respective firmware versions to ensure rapid identification of vulnerable devices.
    • Perform regular backups of device configurations to allow for quick restoration in the event of an incident.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert