Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-54849

Quick assessment

Affected
Socomec DIRIS Digiware M-70
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Socomec DIRIS Digiware M-70是法国Socomec公司的一个多点温度测量模块。 Socomec DIRIS Digiware M-70 1.6.9版本存在访问控制错误漏洞,该漏洞源于Modbus TCP功能存在特制网络请求,可能导致拒绝服务。

CVSS 7.5 · High EPSS 0.31% · P24
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-54849

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network requests can lead to a denial of service. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.An attacker can trigger this denial-of-service condition by sending a single Modbus TCP message to port 502 using the Write Single Register function code (6) to write the value 1 to register 4352. This action changes the Modbus address to 15. After this message is sent, the device will be in a denial-of-service state.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5
Vulnerability Title
Socomec DIRIS Digiware M-70 访问控制错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Socomec DIRIS Digiware M-70是法国Socomec公司的一个多点温度测量模块。 Socomec DIRIS Digiware M-70 1.6.9版本存在访问控制错误漏洞,该漏洞源于Modbus TCP功能存在特制网络请求,可能导致拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Socomec DIRIS Digiware M-70 1.6.9 -

II. Public POCs for CVE-2025-54849

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-54849

登录查看更多情报信息。

Vendor Advisories for CVE-2025-54849 (1)

Same Patch Batch · Socomec · 2025-12-01 · 14 CVEs total

CVE-2024-48882 8.6 HIGH Socomec DIRIS Digiware M-70 安全漏洞
CVE-2025-26858 8.6 HIGH Socomec DIRIS Digiware M-70 安全漏洞
CVE-2025-55221 8.6 HIGH Socomec DIRIS Digiware M-70 访问控制错误漏洞
CVE-2025-55222 8.6 HIGH Socomec DIRIS Digiware M-70 访问控制错误漏洞
CVE-2025-23417 8.6 HIGH Socomec DIRIS Digiware M-70 安全漏洞
CVE-2024-53684 7.5 HIGH Socomec DIRIS Digiware M-70 安全漏洞
CVE-2025-54851 7.5 HIGH Socomec DIRIS Digiware M-70 访问控制错误漏洞
CVE-2025-54848 7.5 HIGH Socomec DIRIS Digiware M-70 访问控制错误漏洞
CVE-2025-54850 7.5 HIGH Socomec DIRIS Digiware M-70 访问控制错误漏洞
CVE-2024-45370 7.3 HIGH Socomec Easy Config System 安全漏洞
CVE-2024-49572 7.2 HIGH Socomec DIRIS Digiware M-70 安全漏洞
CVE-2025-20085 7.2 HIGH Socomec DIRIS Digiware M-70 安全漏洞
CVE-2024-48894 5.9 MEDIUM Socomec DIRIS Digiware M-70 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-54849

No comments yet


Leave a comment