Junglewise Threat Intelligence

CVE-2024-53684: A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially cr

CVE-2024-53684 · Severity: high · CVSS 7.5 · Published 2025-12-01

Technologies: Socomec Diris M-70, Socomec Diris M-70 Firmware. Vendors: Socomec.

Executive brief

A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to unauthorized access. An attacker can stage a malicious webpage to trigger this vulnerability.

Affected products

  • socomec diris_m-70
  • socomec diris_m-70_firmware

Related threats