The Socomec DIRIS Digiware M-70 is an electrical power monitoring gateway used in high-criticality environments, including data centers, industrial plants, and commercial buildings. Its primary function is to provide real-time visibility into electrical systems, enabling energy management, operational monitoring, and fault detection. The importance of this device is high in environments where it is essential to ensure operational continuity and real-time awareness of the state of electrical systems.
The impact of the vulnerability consists of a remote and unauthenticated Denial of Service (DoS). An attacker with network access can disrupt the gateway’s monitoring capabilities, effectively blinding operators to the status of their electrical infrastructure. This can hinder incident response, mask power quality issues, and interfere with energy efficiency programs.
Currently, this vulnerability is not listed in CISA’s KEV (Known Exploited Vulnerabilities) catalog, and there are no public reports of active exploitation. However, the attack is considered simple to execute for an adversary who has gained access to the Operational Technology (OT) network where the device is located. M-70 gateways exposed to the internet or improperly segmented are particularly at risk.
| Product | Socomec DIRIS Digiware M-70 |
| Date | 2025-12-05 00:15:11 |
Technical Summary
The root cause of the vulnerability is a CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) within the device firmware during the parsing of Modbus TCP packets. The service listening on the Modbus port (typically TCP/502) does not correctly verify the size of user-supplied data before copying it into a fixed-length buffer allocated on the stack.
The attack chain is as follows:
- An unauthenticated attacker establishes a network connection with the Modbus TCP service on the Socomec DIRIS Digiware M-70 gateway.
- The attacker sends a specially crafted sequence of packets containing a value larger than the size expected by the service’s buffer.
- The service attempts to process this malformed request, causing a buffer overflow condition.
- This memory corruption overwrites adjacent areas, leading to the immediate crash of the Modbus TCP service and rendering the device unresponsive to further monitoring requests.
An attacker can repeatedly exploit this vulnerability to create a persistent Denial of Service condition, preventing operators from monitoring electrical systems. The only way to restore functionality is to perform a manual power cycle of the device. The vulnerability affects the Socomec DIRIS Digiware M-70 model; users should consult the vendor for specific information on affected firmware versions and the availability of patches.
Recommendations
- Apply patches immediately: Contact Socomec to obtain the latest firmware updates for the DIRIS Digiware M-70 and apply them as soon as possible.
- Mitigations: Implement strict network segmentation to ensure the device is not exposed to the Internet. Limit access to the Modbus TCP port (502) to a restricted set of trusted IP addresses on a dedicated management or OT network.
- Monitoring activities: Monitor firewall and network logs for unauthorized connection attempts to the Modbus TCP port on DIRIS Digiware devices. Investigate any devices that go offline repeatedly or become unresponsive, as this could be a sign of compromise or attempted exploitation.
- Incident response: If you suspect a device has been compromised or it becomes unresponsive, isolate it immediately from the network to prevent lateral movement. If possible, preserve logs and device state for forensic analysis before restarting the system.
- Defense-in-Depth: Ensure that all ICS (Industrial Control Systems) and OT devices are located on properly segmented networks, protected by firewalls, and are not part of the general corporate IT network. Implement Access Control Lists (ACLs) to enforce the principle of least privilege on all network communications.
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
