Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Socomec

First CVE: Oct 9, 2019Active for: 7 yearsTotal CVEs: 24
46.0
VTI Score
High

Socomec manufactures electrical measurement and power-management devices, particularly energy meters and monitoring systems such as the Diris M-70 and Modulys GP product lines that are installed in industrial and commercial infrastructure. The vulnerability exposure concentrates in web and authentication interfaces of these devices, with recurring weaknesses including missing authentication on critical functions, cross-site scripting, cross-site request forgery, cleartext transmission of sensitive data, and information disclosure—a pattern typical of embedded systems where operational interfaces were not designed with modern threat models in mind. The vendor's disclosures show a meaningful share of serious-severity outcomes, reflecting the potential impact of compromise on power-distribution visibility and control. Defenders managing these devices should prioritize network isolation, restrict administrative access, and monitor vendor advisories closely for firmware updates; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
24
Total CVEs
More Total CVEs than 97% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Socomec over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 9, 2019
6 years ago
Most Recent CVE
Dec 1, 2025
235 days ago

Products(11 total)

Top CVEs

Signals from CVEs in this vendor scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-15859CRITICAL
Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the /password.jsn URI.
Oct 9, 20199.857NOYES
CVE-2021-41870HIGH
An issue was discovered in the firmware update form in Socomec REMOTE VIEW PRO 2.0.41.4. An authenticated attacker can bypass a client-side file-type check and upload arbitrary .ph
Dec 15, 20218.828NONO
CVE-2024-53684HIGH
A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to unauthori
Dec 1, 20258.827NONO
CVE-2023-41084CRITICAL
Session management within the web application is incorrect and allows attackers to steal session cookies to perform a multitude of actions that the web app allows on the
Sep 18, 20239.827NONO
CVE-2025-55222HIGH
A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network pack
Dec 1, 20257.526NONO
CVE-2025-55221HIGH
A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network pack
Dec 1, 20257.526NONO
CVE-2025-23417HIGH
A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of ser
Dec 1, 20257.526NONO
CVE-2025-54851HIGH
A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network request
Dec 1, 20257.525NONO
CVE-2025-54850HIGH
A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network request
Dec 1, 20257.525NONO
CVE-2025-54848HIGH
A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network request
Dec 1, 20257.525NONO
View all 24 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products24 CVEs
21%
71%
8%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network24 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low24 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None18 (75.0%)
Unknown0 (0.0%)
Required6 (25.0%)
Privileges Required
Low3 (12.5%)
High0 (0.0%)
None21 (87.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.2% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Socomec.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Socomec — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Socomec's Products

View all 3 CNAs →

Top CWEs