CVE-2026-62650
8.8Siemens · Reyrolle 7SR5
A privilege escalation vulnerability exists in the Reyrolle 7SR5 web interface due to improper server-side authorization checks, allowing authenticated attackers to bypass role-based access controls.
Executive summary
Siemens Reyrolle 7SR5 devices are vulnerable to unauthorized privilege escalation, which could allow a low-privileged authenticated user to gain administrative control.
Vulnerability
This vulnerability involves an authentication bypass using an alternate path or channel (CWE-288), where server-side authorization checks are not properly enforced in the web-based management interface. By manipulating request data, an authenticated, low-privileged remote attacker can escalate their privileges to an administrative level.
Business impact
The exploitation of this vulnerability poses a significant risk to operational technology environments where Reyrolle 7SR5 devices are deployed. With a CVSS score of 8.8, this flaw allows for full administrative compromise, potentially resulting in unauthorized modification of protection settings, disruption of critical infrastructure services, or unauthorized access to sensitive control data.
Remediation
Immediate Action: Update all affected Siemens Reyrolle 7SR5 devices to firmware version V2.70 or later as specified in the vendor security advisory.
Proactive Monitoring: Review web management interface access logs for unusual request patterns or repeated attempts to access administrative endpoints by low-privileged user accounts.
Compensating Controls: Restrict network access to the web-based management interface to authorized management subnets only, and enforce strict multi-factor authentication if supported by the environment.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the potential for full administrative privilege escalation, organizations must prioritize the application of the V2.70 firmware update. Failure to remediate this vulnerability leaves critical infrastructure protection devices exposed to unauthorized manipulation by internal actors or compromised accounts.
More Siemens CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section