CVE-2026-62649

7.5

Siemens · Reyrolle 7SR5

An unauthenticated remote attacker can cause a denial of service on Siemens Reyrolle 7SR5 devices by sending excessive concurrent HTTP requests, leading to a device crash and reboot.

Executive summary

A high-severity resource exhaustion vulnerability in Siemens Reyrolle 7SR5 devices allows unauthenticated remote attackers to trigger a denial of service through improper request handling.

Vulnerability

The web server component fails to implement adequate resource limits or throttling when processing concurrent HTTP requests. This allows an unauthenticated remote attacker to exhaust system resources, resulting in a device crash and subsequent reboot.

Business impact

Successful exploitation results in a denial of service for the affected Reyrolle 7SR5 device. Given the product's role in industrial infrastructure, this disruption could lead to significant operational downtime and loss of visibility into critical systems. With a CVSS score of 7.5, the vulnerability represents a high risk to availability that requires immediate attention.

Remediation

Immediate Action: Update Siemens Reyrolle 7SR5 firmware to version V2.70 or later as specified in the official Siemens security advisory.

Proactive Monitoring: Monitor device logs for abnormal spikes in HTTP traffic or recurring service interruptions that may indicate attempts to exploit resource limits.

Compensating Controls: Restrict network access to the device web management interface to trusted management subnets only using firewall rules or access control lists to prevent unauthenticated access.

Exploitation status

Public Exploit Available: No — exploit_available (false).

Analyst recommendation

The vulnerability poses a clear risk to the stability of industrial control components. Administrators should prioritize upgrading to firmware version V2.70 to resolve the underlying resource management flaw. Until updates can be applied, restricting network exposure of the web server remains the most effective method to mitigate the risk of remote service disruption.

More Siemens CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources