AI analysis
Siemens' Reyrolle 7SR5 protection relay exposes, through its web interface, information that lets an attacker calculate the device's current and past session ID numbers (classified as CWE-306, missing authentication for a critical function). An attacker with network reachability to the web interface needs no privileges or user interaction (AV:N/PR:N/UI:N) and can use the calculated session IDs to bypass authentication and gain unauthorized access to the device. Successful exploitation carries high impact on the confidentiality, integrity, and availability of the affected relay itself (CVSS 4.0 9.3, critical), though the advisory does not describe broader grid impact. All Reyrolle 7SR5 versions below V2.70 are affected, per the Siemens product certification advisory (CNA). No public proof-of-concept, no CISA KEV listing, and a low EPSS (0.3%, 28th percentile) indicate that exploitation has not yet been reported.
What to do: Upgrade Reyrolle 7SR5 devices to firmware V2.70 or later per Siemens' product security notification. Until patched, restrict access to the relay's web interface to trusted engineering/management networks, avoid internet exposure, and monitor for unauthenticated or anomalous sessions. No public PoC or in-the-wild exploitation is known (EPSS 0.3%), but the unauthenticated, network-reachable nature of the flaw justifies prompt patching wherever the web interface is reachable beyond tightly controlled OT segments.
Affected
| Siemens Reyrolle 7SR5 (protection relay) | All versions < V2.70 |
Estimated exposure
moderatelikely thousands to tens of thousands of 7SR5 relays deployed on utility and industrial networks worldwide; the exploitable subset (web interface… — No public install-base, market-share, or internet-exposure scan counts are available in the source data, so the magnitude is inferred from deployment patterns of feeder-protection relays, which typically sit inside utility substation and…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.