CVE-2025-23417: Denial of Service Vulnerability in Socomec DIRIS Digiware M-70 on Modbus RTU over TCP

ISGroup Cybersecurity

The Socomec DIRIS Digiware M-70 is an Industrial Control System (ICS) device specialized for energy monitoring and management in critical infrastructure sectors, including data centers, manufacturing plants, and industrial facilities. Its function is essential for ensuring power quality, managing energy consumption, and providing visibility into electrical systems, making its availability critical for operational continuity.

The primary risk is an unauthenticated, high-impact Denial of Service (DoS), which can be triggered remotely via a single network packet. This allows an attacker with minimal skills to disrupt critical monitoring capabilities, potentially masking serious electrical faults or power quality issues. This could lead to operational outages, increased energy costs, or even damage to equipment in sensitive environments.

Currently, there is no evidence of active exploitation of this vulnerability. However, given the public disclosure of the vulnerability and the low complexity of the attack vector, any DIRIS Digiware M-70 device with the Modbus service exposed to an untrusted network is at serious risk of being targeted. These systems are often treated as “install and forget” and may not be updated regularly, increasing their exposure.

ProductSocomec DIRIS Digiware M-70
Date2025-12-05 00:27:39

Technical Summary

The vulnerability exists in the device’s Modbus RTU over TCP protocol stack handling. The root cause is an input validation error, where the service fails to correctly interpret a specially crafted network packet. This allows an attacker to trigger an unhandled exception or a resource exhaustion state in the firmware, causing the entire device to shut down.

The attack sequence is as follows:

  1. The attacker identifies a Socomec DIRIS Digiware M-70 device on the network.
  2. A single malformed Modbus RTU over TCP packet is sent to the device’s listening service.
  3. The firmware’s parsing logic fails to handle the anomalous data in the packet, causing a system hang or process crash.
  4. The device enters a denial of service state, ceasing all monitoring and communication functions until it is manually restarted.

An unauthenticated attacker with network access can reliably cause a total loss of availability of the target device, disrupting all energy monitoring functionality.

  • Affected firmware: 1.6.9
  • Patched firmware: No patch available at the time of this advisory. Users should consult vendor advisories for updates.

Recommendations

  • Monitor vendor advisories: Since no patch is currently available, subscribe immediately to Socomec security advisories to receive notifications as soon as a corrected firmware version is released.

  • Network segmentation: This is the most critical mitigation. Limit access to the Modbus RTU over TCP service (typically on port 502) to a dedicated, trusted management network. Block all access from untrusted networks, including the Internet, at the firewall level. Do not expose ICS/OT devices directly to the Internet.

  • Hunting and monitoring:

    • Monitor firewall and network traffic logs for any connection attempts to the Modbus service from unauthorized IP addresses or subnets.
    • Establish a baseline of normal Modbus traffic and generate alerts on significant deviations or malformed packets.
    • Monitor the operational status of DIRIS Digiware devices for unexpected reboots or downtime, which could indicate exploitation attempts.

  • Incident response:

    • If a device becomes unresponsive, immediately isolate its network segment to prevent further attacks or lateral movement.
    • Before restarting, capture network traffic if possible to assist in forensic analysis.
    • After restarting to restore service, examine logs to identify the source IP address of the attack and apply blocking rules.

  • Defense in depth:

    • Apply strict Access Control Lists (ACLs) on switches and routers for all OT network segments.
    • Maintain up-to-date configuration backups to allow for rapid restoration if a device needs to be reset or replaced.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert