Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Socomec — Vulnerabilities & Security Advisories 25

Browse all 25 CVE security advisories affecting Socomec. AI-powered Chinese analysis, POCs, and references for each vulnerability.

SOCOMEC specializes in power management and electrical distribution solutions, primarily serving industrial, commercial, and residential sectors with uninterruptible power supplies (UPS) and energy monitoring systems. Security audits reveal a concerning history of twenty-five recorded Common Vulnerabilities and Exposures (CVEs), indicating persistent weaknesses in their product lifecycle. The most prevalent vulnerability classes involve remote code execution (RCE) and cross-site scripting (XSS), often stemming from insufficient input validation in web-based management interfaces. Additionally, several instances of privilege escalation have been documented, allowing unauthorized users to gain administrative control over critical infrastructure components. These flaws frequently reside in the embedded web servers and communication protocols used for device configuration. While no single catastrophic public breach has been widely reported, the accumulation of these CVEs suggests systemic issues in secure coding practices. Organizations deploying SOCOMEC equipment must prioritize network segmentation and regular firmware updates to mitigate the risk of exploitation within their operational technology environments.

CVE IDTitleCVSSSeverityPublished
CVE-2026-2491 Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability — DIRIS A-40CWE-306 8.8AIHighAI2026-03-13
CVE-2024-48894 Socomec DIRIS Digiware M-70 安全漏洞 — DIRIS Digiware M-70CWE-319 5.9 Medium2025-12-01
CVE-2024-53684 Socomec DIRIS Digiware M-70 安全漏洞 — DIRIS Digiware M-70CWE-352 7.5 High2025-12-01
CVE-2024-45370 Socomec Easy Config System 安全漏洞 — Easy Config SystemCWE-302 7.3 High2025-12-01
CVE-2024-49572 Socomec DIRIS Digiware M-70 安全漏洞 — DIRIS Digiware M-70CWE-306 7.2 High2025-12-01
CVE-2024-48882 Socomec DIRIS Digiware M-70 安全漏洞 — DIRIS Digiware M-70CWE-306 8.6 High2025-12-01
CVE-2025-20085 Socomec DIRIS Digiware M-70 安全漏洞 — DIRIS Digiware M-70CWE-306 7.2 High2025-12-01
CVE-2025-23417 Socomec DIRIS Digiware M-70 安全漏洞 — DIRIS Digiware M-70CWE-306 8.6 High2025-12-01
CVE-2025-26858 Socomec DIRIS Digiware M-70 安全漏洞 — DIRIS Digiware M-70CWE-20 8.6 High2025-12-01
CVE-2025-54851 Socomec DIRIS Digiware M-70 访问控制错误漏洞 — DIRIS Digiware M-70CWE-306 7.5 High2025-12-01
CVE-2025-54848 Socomec DIRIS Digiware M-70 访问控制错误漏洞 — DIRIS Digiware M-70CWE-306 7.5 High2025-12-01
CVE-2025-54850 Socomec DIRIS Digiware M-70 访问控制错误漏洞 — DIRIS Digiware M-70CWE-306 7.5 High2025-12-01
CVE-2025-54849 Socomec DIRIS Digiware M-70 访问控制错误漏洞 — DIRIS Digiware M-70CWE-306 7.5 High2025-12-01
CVE-2025-55222 Socomec DIRIS Digiware M-70 访问控制错误漏洞 — DIRIS Digiware M-70CWE-306 8.6 High2025-12-01
CVE-2025-55221 Socomec DIRIS Digiware M-70 访问控制错误漏洞 — DIRIS Digiware M-70CWE-306 8.6 High2025-12-01
CVE-2024-4601 Improper Authentication vulnerability in Socomec Net Vision — Net visionCWE-287 6.7 Medium2024-05-07
CVE-2024-4600 Cross-Site Request Forgery vulnerability in Socomec Net Vision — Net visionCWE-352 7.1 High2024-05-07
CVE-2023-38255 Socomec MOD3GP-SY-120K Cross-site Scripting — MODULYS GP (MOD3GP-SY-120K)CWE-79 6.5 Medium2023-09-18
CVE-2023-38582 Socomec MOD3GP-SY-120K Cross-site Scripting — MODULYS GP (MOD3GP-SY-120K)CWE-79 6.3 Medium2023-09-18
CVE-2023-39446 Socomec MOD3GP-SY-120K Cross-Site Request Forgery — MODULYS GP (MOD3GP-SY-120K)CWE-352 8.9 High2023-09-18
CVE-2023-39452 Socomec MOD3GP-SY-120K Plaintext Storage of a Password — MODULYS GP (MOD3GP-SY-120K)CWE-256 7.5 High2023-09-18
CVE-2023-40221 Socomec MOD3GP-SY-120K Code Injection — MODULYS GP (MOD3GP-SY-120K)CWE-94 8.8 High2023-09-18
CVE-2023-41084 Socomec MOD3GP-SY-120K Reliance on Cookies without Validation and Integrity Checking — MODULYS GP (MOD3GP-SY-120K)CWE-565 10.0 Critical2023-09-18
CVE-2023-41965 Socomec MOD3GP-SY-120K Insecure Storage of Sensitive Information — MODULYS GP (MOD3GP-SY-120K)CWE-921 7.5 High2023-09-18
CVE-2023-0356 Socomec MODULYS GP 安全漏洞 — MODULYS GP CWE-261 5.7 Medium2023-01-24

This page lists every published CVE security advisory associated with Socomec. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.