Cisco Talos disclosed six denial-of-service vulnerabilities (six CVEs) affecting the Socomec DIRIS M-70 industrial gateway used for power monitoring and energy management, with impact concentrated in environments such as critical infrastructure, data centers, and healthcare. The issues affect firmware 1.6.9 and can be triggered remotely without authentication, potentially disrupting Modbus-related processing and causing operational outages or instability in deployments where the gateway is a key communications component (RS485/Ethernet; protocols including Modbus RTU/TCP, BACnet IP, and SNMP).
The research describes a technique to overcome hardware debugging constraints caused by the device’s STM32 Code Read-out Protection (RDP) Level 1, which blocks traditional JTAG-based inspection. Talos obtained an unencrypted firmware update and used a “good enough” emulation strategy: emulating only the single Modbus-handling thread (rather than full-system emulation) with Unicorn Engine, then applying coverage-guided fuzzing with AFL and using Qiling to visualize coverage and analyze crash root causes. Socomec reportedly patched the vulnerabilities following coordinated disclosure via Cisco’s policy.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Detection content was made available in the form of Snort rules to help identify attempts to exploit the DIRIS M-70 vulnerabilities. This accompanied public reporting on the six Modbus-related DoS flaws.
The six vulnerabilities were disclosed under Cisco's coordinated disclosure process and assigned CVEs. Socomec released patches and advised customers to upgrade to firmware version 1.7 or later to remediate the issues.
The fuzzing campaign uncovered six denial-of-service flaws in Socomec DIRIS M-70 firmware version 1.6.9. The issues allow unauthenticated remote attackers to crash or render the device inoperable by sending crafted Modbus messages over the network.
While analyzing the Socomec DIRIS M-70 industrial gateway, a Cisco Talos researcher used an unencrypted firmware update and SRAM dumping to work around STM32 RDP Level 1 protections, then emulated only the Modbus-handling thread with Unicorn and AFL. The approach was later adapted to Qiling to improve debugging and code-coverage visualization during crash triage and root-cause analysis.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceblog.talosintelligence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.