ZeroHour

CVE-2026-62645

moderate

Predictable Session IDs in Siemens Reyrolle 7SR5 Allow Authentication Bypass

CVSS 4.0
9.3 critical
EPSS
<1%p28
Published
()
Modified
AI analysis

Siemens' Reyrolle 7SR5 protection relay exposes, through its web interface, information that lets an attacker calculate the device's current and past session ID numbers (classified as CWE-306, missing authentication for a critical function). An attacker with network reachability to the web interface needs no privileges or user interaction (AV:N/PR:N/UI:N) and can use the calculated session IDs to bypass authentication and gain unauthorized access to the device. Successful exploitation carries high impact on the confidentiality, integrity, and availability of the affected relay itself (CVSS 4.0 9.3, critical), though the advisory does not describe broader grid impact. All Reyrolle 7SR5 versions below V2.70 are affected, per the Siemens product certification advisory (CNA). No public proof-of-concept, no CISA KEV listing, and a low EPSS (0.3%, 28th percentile) indicate that exploitation has not yet been reported.

What to do: Upgrade Reyrolle 7SR5 devices to firmware V2.70 or later per Siemens' product security notification. Until patched, restrict access to the relay's web interface to trusted engineering/management networks, avoid internet exposure, and monitor for unauthenticated or anomalous sessions. No public PoC or in-the-wild exploitation is known (EPSS 0.3%), but the unauthenticated, network-reachable nature of the flaw justifies prompt patching wherever the web interface is reachable beyond tightly controlled OT segments.

Affected
Siemens Reyrolle 7SR5 (protection relay)All versions < V2.70
Estimated exposure
moderatelikely thousands to tens of thousands of 7SR5 relays deployed on utility and industrial networks worldwide; the exploitable subset (web interface… — No public install-base, market-share, or internet-exposure scan counts are available in the source data, so the magnitude is inferred from deployment patterns of feeder-protection relays, which typically sit inside utility substation and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Information is exposed through the web interface that can be used to calculate the current and past session ID numbers. This could allow an attacker to bypass the authentication and gain unauthorized access to the device.

Weakness
CWE-306
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Siemens Reyrolle 7SR5

CISA advisory covers 14 vulnerabilities, CVSS 9.8, in Siemens Reyrolle 7SR5 energy-sector protection relays before V2.70.

CISA advisory ICSA-26-258-05 covers 14 vulnerabilities in Siemens Reyrolle 7SR5 protection relays before V2.70, used in the energy sector worldwide, with aggregate CVSS v3 of 9.8. Flaws include Cesanta Mongoose web server issues (CVE-2024-42384 through CVE-2024-42392) and new bugs such as web-interface session-ID exposure enabling authentication bypass (CVE-2026-62645, CVSS 9.8), predictable session tokens (CVE-2026-62646, CVE-2026-62647), and pre-auth out-of-bounds writes (CVE-2026-62648). Siemens has released V2.70 and recommends updating to the latest version.