CVE-2025-20085 Details
Description
A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service and weaken credentials resulting in default documented credentials being applied to the device. An attacker can send an unauthenticated packet to trigger this vulnerability.
A denial-of-service vulnerability has been identified in the Socomec DIRIS Digiware M-70 version 1.6.9. This issue arises in the Modbus RTU over TCP functionality, where a specially crafted network packet can disrupt service and weaken device credentials, causing default documented credentials to be reapplied. The vulnerability can be exploited by sending an unauthenticated packet via the Modbus RTU over TCP protocol.
Users can disable the writing capability over Modbus RTU over TCP by using the Cyber Security user profile in the DIRIS Digiware M-70 WEBVIEW-M interface. This change will also disable writing over ModbusTCP on port 502.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 1, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| socomec diris m-70 firmware | 1.6.9 |
CPE
Remediation
| |
| socomec diris m-70 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 26, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 5, 2025 | Initial Analysis | [email protected] |
| Dec 1, 2025 | CVE Modified | CVE |
| Dec 1, 2025 | New CVE Received | [email protected] |