CVE-2026-62646
7.4Siemens · Reyrolle 7SR5
Siemens Reyrolle 7SR5 devices generate session tokens with insufficient entropy, allowing unauthenticated remote attackers to predict identifiers and bypass authentication.
Executive summary
A critical authentication bypass vulnerability in Siemens Reyrolle 7SR5 devices allows unauthenticated remote attackers to hijack sessions due to predictable token generation.
Vulnerability
The device suffers from insufficient entropy in its session identifier generation algorithm, which permits an unauthenticated remote attacker to predict or brute force valid session tokens to bypass security controls.
Business impact
Successful exploitation grants an unauthorized attacker the ability to hijack legitimate user sessions, potentially leading to unauthorized control over critical infrastructure management functions. With a CVSS score of 7.4, this high-severity flaw poses a significant risk to operational integrity and system confidentiality. Unauthorized access to industrial protection devices can result in severe service disruption or physical process manipulation.
Remediation
Immediate Action: Update all affected Siemens Reyrolle 7SR5 devices to firmware version V2.70 or later immediately to resolve the entropy issue.
Proactive Monitoring: Monitor device access logs for high volumes of failed login attempts or unusual session initiation patterns that may indicate brute force activity.
Compensating Controls: Restrict network access to the device management interface to trusted administrative segments only to reduce the attack surface for remote, unauthenticated actors.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
Given the potential for unauthorized administrative access to critical infrastructure, organizations must prioritize the application of firmware version V2.70. Administrators should verify the current version of all deployed units and schedule maintenance windows to ensure the patch is applied without delay to mitigate the risk of session hijacking.
More Siemens CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section