← CVE Tracker
7.5HIGH

CVE-2025-54849 — A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of…

Socomec · Diris Digiware M-70 Firmware · Published 1 Dec 2025 · Modified 26 Sept 2026

Description

A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network requests can lead to a denial of service. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.An attacker can trigger this denial-of-service condition by sending a single Modbus TCP message to port 502 using the Write Single Register function code (6) to write the value 1 to register 4352. This action changes the Modbus address to 15. After this message is sent, the device will be in a denial-of-service state.

References

What to do
  1. Check whether Diris Digiware M-70 Firmware is in your asset inventory.
  2. Patch in the next maintenance window; prioritise internet-facing systems.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2025-54849