SB2025120218 - Multiple vulnerabilities in Socomec DIRIS Digiware M-70



SB2025120218 - Multiple vulnerabilities in Socomec DIRIS Digiware M-70

Published: December 2, 2025

Security Bulletin ID SB2025120218
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 13
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 77% Low 8% 15%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 13 vulnerabilities.


1) Missing Authentication for Critical Function (CVE-ID: CVE-2024-48882)

CWE-ID: CWE-306 - Missing Authentication for Critical Function

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to missing authentication for critical function in the Modbus TCP functionality. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


2) Missing Authentication for Critical Function (CVE-ID: CVE-2025-20085)

CWE-ID: CWE-306 - Missing Authentication for Critical Function

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to missing authentication for critical function in the Modbus RTU over TCP functionality. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


3) Buffer overflow (CVE-ID: CVE-2025-26858)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary error in the Modbus TCP functionality. A remote attacker can trigger memory corruption and cause a denial of service condition on the target system.


4) Missing Authentication for Critical Functionh (CVE-ID: CVE-2025-23417)

CWE-ID: CWE-306 - Missing Authentication for Critical Function

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to missing authentication for critical function in the Modbus RTU over TCP functionality. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


5) Missing Authentication for Critical Function (CVE-ID: CVE-2025-55221)

CWE-ID: CWE-306 - Missing Authentication for Critical Function

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to missing authentication for critical function in the Modbus TCP functionality. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


6) Missing Authentication for Critical Function (CVE-ID: CVE-2025-55222)

CWE-ID: CWE-306 - Missing Authentication for Critical Function

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to missing authentication for critical function in the Modbus RTU over TCP USB Function functionality. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


7) Cleartext transmission of sensitive information (CVE-ID: CVE-2024-48894)

CWE-ID: CWE-319 - Cleartext Transmission of Sensitive Information

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to software uses insecure communication channel to transmit sensitive information in the WEBVIEW-M functionality. A remote attacker can gain access to sensitive data.


8) Missing Authentication for Critical Function (CVE-ID: CVE-2024-49572)

CWE-ID: CWE-306 - Missing Authentication for Critical Function

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to missing authentication for critical function in the Modbus TCP functionality. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


9) Missing Authentication for Critical Function (CVE-ID: CVE-2025-54851)

CWE-ID: CWE-306 - Missing Authentication for Critical Function

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:U


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to missing authentication for critical function in the Modbus TCP and Modbus RTU over TCP functionality within UPS Default settings. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


10) Missing Authentication for Critical Function (CVE-ID: CVE-2025-54850)

CWE-ID: CWE-306 - Missing Authentication for Critical Function

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:U


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to missing authentication for critical function in the Modbus TCP and Modbus RTU over TCP functionality within Modbus Address modification. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


11) Missing Authentication for Critical Function (CVE-ID: CVE-2025-54849)

CWE-ID: CWE-306 - Missing Authentication for Critical Function

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to missing authentication for critical function in the Modbus TCP and Modbus RTU over TCP functionality within UPS Default settings. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


12) Missing Authentication for Critical Function (CVE-ID: CVE-2025-54848)

CWE-ID: CWE-306 - Missing Authentication for Critical Function

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to missing authentication for critical function in the Modbus TCP and Modbus RTU over TCP functionality within Modbus Address modification. A remote attacker can pass specially crafted input to the application and perform a denial of service (DoS) attack.


13) Cross-site request forgery (CVE-ID: CVE-2024-53684)

CWE-ID: CWE-352 - Cross-Site Request Forgery (CSRF)

CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/U:Clear


The vulnerability allows a remote attacker to perform cross-site request forgery attacks.

The vulnerability exists due to insufficient validation of the HTTP request origin in the WEBVIEW-M functionality. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website.


Remediation

Install update from vendor's website.