CVE-2026-62650

8.8

Siemens · Reyrolle 7SR5

A privilege escalation vulnerability exists in the Reyrolle 7SR5 web interface due to improper server-side authorization checks, allowing authenticated attackers to bypass role-based access controls.

Executive summary

Siemens Reyrolle 7SR5 devices are vulnerable to unauthorized privilege escalation, which could allow a low-privileged authenticated user to gain administrative control.

Vulnerability

This vulnerability involves an authentication bypass using an alternate path or channel (CWE-288), where server-side authorization checks are not properly enforced in the web-based management interface. By manipulating request data, an authenticated, low-privileged remote attacker can escalate their privileges to an administrative level.

Business impact

The exploitation of this vulnerability poses a significant risk to operational technology environments where Reyrolle 7SR5 devices are deployed. With a CVSS score of 8.8, this flaw allows for full administrative compromise, potentially resulting in unauthorized modification of protection settings, disruption of critical infrastructure services, or unauthorized access to sensitive control data.

Remediation

Immediate Action: Update all affected Siemens Reyrolle 7SR5 devices to firmware version V2.70 or later as specified in the vendor security advisory.

Proactive Monitoring: Review web management interface access logs for unusual request patterns or repeated attempts to access administrative endpoints by low-privileged user accounts.

Compensating Controls: Restrict network access to the web-based management interface to authorized management subnets only, and enforce strict multi-factor authentication if supported by the environment.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS score and the potential for full administrative privilege escalation, organizations must prioritize the application of the V2.70 firmware update. Failure to remediate this vulnerability leaves critical infrastructure protection devices exposed to unauthorized manipulation by internal actors or compromised accounts.

More Siemens CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources