CVE-2026-62648

7.5

Siemens · Reyrolle 7SR5

An out-of-bounds write vulnerability in the Siemens Reyrolle 7SR5 device allows unauthenticated remote attackers to trigger a denial-of-service condition via a crafted HTTP message.

Executive summary

An unauthenticated remote denial-of-service vulnerability in Siemens Reyrolle 7SR5 devices poses a significant risk to operational continuity due to potential device crashes.

Vulnerability

This vulnerability is an out-of-bounds write flaw caused by improper validation of URL component lengths in pre-authenticated HTTP messages. An unauthenticated remote attacker can exploit this to crash the device, necessitating a reboot.

Business impact

The vulnerability carries a CVSS score of 7.5, reflecting its high impact on system availability. Successful exploitation results in a denial-of-service, which in an industrial or utility environment, can lead to critical process interruptions, loss of visibility, and operational downtime.

Remediation

Immediate Action: Update the Siemens Reyrolle 7SR5 firmware to version V2.70 or later as specified in the official vendor advisory.

Proactive Monitoring: Monitor network traffic for malformed HTTP requests and review system logs for recurring reboot events or unexpected device restarts.

Compensating Controls: Deploy network segmentation and perimeter firewall rules to restrict access to the device management interface, ensuring only authorized management stations can communicate with the Reyrolle 7SR5.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for remote denial-of-service attacks against critical infrastructure components, organizations using the Siemens Reyrolle 7SR5 should prioritize the deployment of the V2.70 firmware update. Immediate patching is necessary to eliminate the risk of unauthorized device disruption and to maintain the integrity of the operational technology environment.

More Siemens CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources