Cyber Security News

Selective Thread Emulation and Fuzzing Expose DoS Flaws in Socomec DIRIS M-70 IIoT Device

Security researchers have uncovered six critical denial-of-service vulnerabilities in the Socomec DIRIS M-70 industrial gateway used for power monitoring and energy management in critical infrastructure.

The flaws were discovered through an innovative emulation technique that bypassed hardware debugging limitations by focusing on a single thread handling Modbus protocol communications.

The M-70 gateway facilitates data communication over RS485 and Ethernet networks while supporting multiple industrial communication protocols including Modbus RTU, Modbus TCP, BACnet IP, and SNMP.

The vulnerabilities affect firmware version 1.6.9 and could allow remote attackers to disrupt device operations without authentication.

These flaws pose severe risks to sectors like data centers, healthcare facilities, and critical infrastructure where the gateway serves as a vital component for energy management.

A compromised gateway could lead to widespread outages, operational disruption, and equipment damage in industrial environments.

Cisco Talos researchers identified the vulnerabilities after encountering Code Read-out Protection (RDP) Level 1 on the device’s STM32 microcontroller, which prevented traditional debugging through JTAG connections.

RDP Level 1 debug output (Source – Cisco Talos)

This protection mechanism blocks flash memory reads while debugger access is detected, making it impossible to examine code during execution.

The researchers obtained an unencrypted firmware update file that provided the necessary code for analysis.

The research team developed a targeted emulation approach using the Unicorn Engine framework to run only the Modbus processing thread rather than attempting full system emulation.

This strategy proved effective for vulnerability discovery while requiring significantly less development time.

The researchers integrated AFL (American Fuzzy Lop) for coverage-guided fuzzing and later transitioned to the Qiling framework, which added debugging capabilities and code coverage visualization.

Unicorn AFL integration (Source – Cisco Talos)

The Modbus thread supported over 700 unique message types, making manual inspection impractical.

Vulnerability Details and Impact

The fuzzing campaign successfully identified six vulnerabilities tracked as CVE-2025-54848, CVE-2025-54849, CVE-2025-54850, CVE-2025-54851, CVE-2025-55221, and CVE-2025-55222.

Each vulnerability carries a CVSS v3.1 score of 7.5 (HIGH) with network-based attack vectors requiring low complexity and no user interaction.

The flaws allow unauthenticated attackers to send specially crafted Modbus TCP or Modbus RTU over TCP messages that trigger denial-of-service conditions, rendering the device inoperable.

Unicorn to Qiling API changes (Source – Cisco Talos)

Socomec has released patches for all affected products following disclosure under Cisco’s Coordinated Disclosure Policy.

Users running firmware version 1.6.9 should immediately update to version 1.7 or later to protect against exploitation.

Organizations can also deploy SNORT detection rules available from Snort.org to identify potential exploitation attempts targeting these vulnerabilities in their network environments.

The research demonstrates how focused emulation targeting specific vulnerable components can achieve impactful vulnerability discovery without requiring complete system emulation.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago