Cyber Posture

CVE-2024-48882

High

Published: 01 December 2025

Published
01 December 2025
Modified
05 December 2025
KEV Added
Patch
CVSS Score 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
EPSS Score 0.0006 19.5th percentile
Risk Priority 17 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users.

Security Summary

CVE-2024-48882 is a denial-of-service vulnerability in the Modbus TCP functionality of the Socomec DIRIS Digiware M-70 device running version 1.6.9. The issue arises when a specially crafted network packet is processed, leading to a denial of service. Exploitation requires no authentication, as an attacker can trigger the vulnerability by sending a malicious packet directly to the affected component.

A remote attacker with network access to the device can exploit this vulnerability without privileges or user interaction. Successful exploitation results in a denial of service, disrupting availability with a CVSS v3.1 base score of 8.6 (AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H). The changed scope (S:C) indicates potential impact beyond the vulnerable component, classified under CWE-306 (Missing Authentication for Critical Function).

Mitigation details are available in the Cisco Talos Intelligence report (TALOS-2024-2119) and the official Socomec advisory document, which address patches and remediation steps for the DIRIS Digiware M-70.

Details

CWE(s)
CWE-306

Affected Products

socomec
diris m-70 firmware
1.6.9

MITRE ATT&CK Enterprise Techniques

T1499.004 Application or System Exploitation Impact
Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users.
Why these techniques?

The vulnerability enables remote unauthenticated denial of service via a specially crafted Modbus TCP packet, directly facilitating Endpoint Denial of Service through application or system exploitation.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References