A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service and weaken credentials resulting in default documented credentials being applied to the device. An attacker can send an unauthenticated packet to trigger this vulnerability.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 01 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Socomec
Socomec diris M-70
Vendors & Products Socomec
Socomec diris M-70

Mon, 01 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 01 Dec 2025 17:30:00 +0000


Mon, 01 Dec 2025 15:45:00 +0000

Type Values Removed Values Added
Description A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service and weaken credentials resulting in default documented credentials being applied to the device. An attacker can send an unauthenticated packet to trigger this vulnerability.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published:

Updated: 2025-12-01T20:20:41.234Z

Reserved: 2025-01-22T19:55:34.239Z

Link: CVE-2025-20085

cve-icon Vulnrichment

Updated: 2025-12-01T17:05:41.574Z

cve-icon NVD

Status : Received

Published: 2025-12-01T16:15:51.960

Modified: 2025-12-01T17:15:48.923

Link: CVE-2025-20085

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-01T21:27:20Z