Socomec manufactures electrical measurement and power-management devices, particularly energy meters and monitoring systems such as the Diris M-70 and Modulys GP product lines that are installed in industrial and commercial infrastructure. The vulnerability exposure concentrates in web and authentication interfaces of these devices, with recurring weaknesses including missing authentication on critical functions, cross-site scripting, cross-site request forgery, cleartext transmission of sensitive data, and information disclosure—a pattern typical of embedded systems where operational interfaces were not designed with modern threat models in mind. The vendor's disclosures show a meaningful share of serious-severity outcomes, reflecting the potential impact of compromise on power-distribution visibility and control. Defenders managing these devices should prioritize network isolation, restrict administrative access, and monitor vendor advisories closely for firmware updates; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Socomec over time
Signals from CVEs in this vendor scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-15859CRITICAL Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the /password.jsn URI. | Oct 9, 2019 | 9.8 | 57 | NO | YES |
CVE-2021-41870HIGH An issue was discovered in the firmware update form in Socomec REMOTE VIEW PRO 2.0.41.4. An authenticated attacker can bypass a client-side file-type check and upload arbitrary .ph | Dec 15, 2021 | 8.8 | 28 | NO | NO |
CVE-2024-53684HIGH A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to unauthori | Dec 1, 2025 | 8.8 | 27 | NO | NO |
CVE-2023-41084CRITICAL
Session management within the web application is incorrect and allows attackers to steal session cookies to perform a multitude of actions that the web app allows on the | Sep 18, 2023 | 9.8 | 27 | NO | NO |
CVE-2025-55222HIGH A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network pack | Dec 1, 2025 | 7.5 | 26 | NO | NO |
CVE-2025-55221HIGH A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP USB Function functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network pack | Dec 1, 2025 | 7.5 | 26 | NO | NO |
CVE-2025-23417HIGH A denial of service vulnerability exists in the Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted network packet can lead to denial of ser | Dec 1, 2025 | 7.5 | 26 | NO | NO |
CVE-2025-54851HIGH A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network request | Dec 1, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-54850HIGH A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network request | Dec 1, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-54848HIGH A denial of service vulnerability exists in the Modbus TCP and Modbus RTU over TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted series of network request | Dec 1, 2025 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (24 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Socomec.
Media articles that mention a CVE ID that affects a product developed by Socomec — matched by CVE ID, not by vendor name.