CVE-2019-15859: Socomec Diris A-40 Firmware

Critical severity, CVSS 9.8. EPSS: 31.5% chance of exploitation in the next 30 days.

Password disclosure in the web interface on socomec DIRIS A-40 devices before 48250501 allows a remote attacker to get full access to a device via the /password.jsn URI.

Affected products

  • Socomec Diris A-40 Firmware: before 48250501 (fixed in 48250501)

Published 2019-10-09. Last modified 2026-06-17.