---
id: CVE-2025-20085
title: >-
  A denial of service vulnerability exists in the Modbus RTU over TCP
  functionality of Socomec DIRIS Digiware M-70 1.6.9
summary: >-
  A denial of service vulnerability exists in the Modbus RTU over TCP
  functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted
  network packet can lead to denial of service and weaken credentials resulting
  in default document…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-306
vendor: socomec
product: diris_m-70_firmware
affected:
  - diris_m-70_firmware = 1.6.9
published: '2025-12-01'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T00:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-20085'
references:
  - url: 'https://talosintelligence.com/vulnerability_reports/TALOS-2025-2138'
    label: talos-cna@cisco.com
  - url: >-
      https://www.socomec.fr/sites/default/files/2025-04/CVE-2025-20085---Diris-Digiware-Webview-_VULNERABILITIES_2025-04-11-17-14-39_English_0.pdf
    label: talos-cna@cisco.com
  - url: 'https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2138'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00343
epssPercentile: 0.25109
ingestedAt: '2026-09-26T00:22:39.982Z'
---

## Overview

A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service and weaken credentials resulting in default documented credentials being applied to the device. An attacker can send an unauthenticated packet to trigger this vulnerability.

## Affected

- `diris_m-70_firmware = 1.6.9`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
