CVE-2026-62647

7.4

Siemens · Reyrolle 7SR5

A predictable random number generator in Siemens Reyrolle 7SR5 devices allows unauthenticated remote attackers to guess session identifiers and impersonate legitimate users.

Executive summary

A critical authentication bypass vulnerability in Siemens Reyrolle 7SR5 devices allows remote, unauthenticated attackers to hijack sessions by predicting security-relevant values.

Vulnerability

The device uses a cryptographically weak random number generator for session identifiers instead of a True Random Number Generator. This flaw allows an unauthenticated remote attacker to predict session tokens and gain unauthorized access to the device.

Business impact

The ability for an attacker to impersonate a legitimate user on industrial equipment poses a severe risk to operational integrity. Given the CVSS score of 7.4, this high-severity flaw could lead to unauthorized control of protective relay settings, resulting in operational downtime, safety risks, or permanent damage to electrical infrastructure.

Remediation

Immediate Action: Update the Siemens Reyrolle 7SR5 firmware to version V2.70 or later as specified in the official Siemens security advisory.

Proactive Monitoring: Monitor device access logs for unusual patterns, such as multiple rapid authentication attempts or sessions appearing from unexpected network segments.

Compensating Controls: Restrict network access to the device management interface by implementing strict firewall rules and isolating the management plane from the general business network.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability represents a significant risk to the security of power grid infrastructure components. Organizations utilizing the Reyrolle 7SR5 must prioritize the deployment of firmware version V2.70 to remediate the underlying weakness in session management. Failure to update leaves these devices exposed to unauthorized remote access and potential manipulation of critical safety settings.

More Siemens CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources