Vulnerability Description
A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network requests can lead to a denial of service. An attacker can send a sequence of unauthenticated packets to trigger this vulnerability.An attacker can trigger this denial-of-service condition by sending a single Modbus TCP message to port 502 using the Write Single Register function code (6) to write the value 1 to register 4352. This action changes the Modbus address to 15. After this message is sent, the device will be in a denial-of-service state.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Socomec | Diris Digiware M-70 Firmware | 1.6.9 |
| Socomec | Diris Digiware M-70 | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-54849?
CVE-2025-54849 is a vulnerability with a CVSS score of 7.5 (HIGH). A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network requests can lead to a deni...
How severe is CVE-2025-54849?
CVE-2025-54849 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-54849?
Check the references section above for vendor advisories and patch information. Affected products include: Socomec Diris Digiware M-70 Firmware, Socomec Diris Digiware M-70.