A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to a denial of service. An attacker can send an unauthenticated packet to trigger this vulnerability.This vulnerability is specific to the malicious message sent via Modbus RTU over TCP on port 503.
History

Mon, 01 Dec 2025 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Socomec
Socomec diris M-70
Vendors & Products Socomec
Socomec diris M-70

Mon, 01 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 01 Dec 2025 15:45:00 +0000

Type Values Removed Values Added
Description A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to a denial of service. An attacker can send an unauthenticated packet to trigger this vulnerability.This vulnerability is specific to the malicious message sent via Modbus RTU over TCP on port 503.
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: talos

Published: 2025-12-01T15:25:07.167Z

Updated: 2025-12-01T20:15:09.010Z

Reserved: 2025-08-11T15:04:59.033Z

Link: CVE-2025-55222

cve-icon Vulnrichment

Updated: 2025-12-01T20:15:02.815Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-01T16:15:54.620

Modified: 2025-12-02T17:16:29.163

Link: CVE-2025-55222

cve-icon Redhat

No data.