CVE-2025-20085 – Socomec DIRIS Digiware M-70 Modbus RTU over TCP Denial of Service and Authentication Bypass Vulnerability

The following table lists the changes that have been made to the
CVE-2025-20085 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • CVE Modified
    by af854a3a-2127-422b-91ae-364da2661108

    Dec. 01, 2025

    Action Type Old Value New Value
    Added Reference https://www.talosintelligence.com/vulnerability_reports/TALOS-2025-2138
  • New CVE Received
    by [email protected]

    Dec. 01, 2025

    Action Type Old Value New Value
    Added Description A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of service and weaken credentials resulting in default documented credentials being applied to the device. An attacker can send an unauthenticated packet to trigger this vulnerability.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
    Added CWE CWE-306
    Added Reference https://talosintelligence.com/vulnerability_reports/TALOS-2025-2138
    Added Reference https://www.socomec.fr/sites/default/files/2025-04/CVE-2025-20085—Diris-Digiware-Webview-_VULNERABILITIES_2025-04-11-17-14-39_English_0.pdf
Share the Post:

Related Posts