ZeroHour

CVE-2026-62647

Predictable Session Identifiers in Siemens Reyrolle 7SR5 Allow User Impersonation

CVSS 4.0
9.3 critical
EPSS
<1%p27
Published
()
Modified
AI analysis

Siemens Reyrolle 7SR5 protection relays running all versions prior to V2.70 generate security-relevant values, including authentication session identifiers, using a random number generator that is not seeded by a True Random Number Generator, so the generated sequence is predictable. An unauthenticated remote attacker with network reachability to the device can predict these values and impersonate a legitimately authenticated user, gaining unauthorized access to the relay with high impact on confidentiality and integrity (CVSS 4.0: 9.3, critical). The attack requires no privileges or user interaction and is rated low attack complexity over the network. Affected users are operators of Reyrolle 7SR5 relays, which are typically deployed for feeder protection in utility and industrial substation environments. Exploitation status: no public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation within 30 days, so no in-the-wild exploitation is currently known.

What to do: Upgrade affected Reyrolle 7SR5 relays to firmware V2.70 or later, which seeds security-relevant values from a TRNG. Until patched, restrict network access to the relay's management interface via firewalling or OT network segmentation, since exploitation requires remote reachability, and verify deployed firmware versions across your fleet. Monitor authentication logs for signs of session impersonation or anomalous authenticated sessions.

Affected
Siemens Reyrolle 7SR5All versions < V2.70
Estimated exposure
unknown — likely on the order of thousands of deployed relays worldwide, with only a small subset remotely reachable (estimate) — No public install-base counts or internet-exposure scan data exist for this product; the estimate is based on the deployment pattern of substation protection relays, which usually sit on utility operational technology networks rather than…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A random number generator is used to generate security-relevant values (such as session identifiers used for authentication purposes) that is not initialized with a True Random Number Generator (TRNG), resulting in a predictable sequence of generated values. This could allow an unauthenticated remote attacker to more easily predict the generated values and impersonate a legitimate authenticated user, potentially gaining unauthorized access to the device.

Weakness
CWE-20
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Siemens Reyrolle 7SR5

CISA advisory covers 14 vulnerabilities, CVSS 9.8, in Siemens Reyrolle 7SR5 energy-sector protection relays before V2.70.

CISA advisory ICSA-26-258-05 covers 14 vulnerabilities in Siemens Reyrolle 7SR5 protection relays before V2.70, used in the energy sector worldwide, with aggregate CVSS v3 of 9.8. Flaws include Cesanta Mongoose web server issues (CVE-2024-42384 through CVE-2024-42392) and new bugs such as web-interface session-ID exposure enabling authentication bypass (CVE-2026-62645, CVSS 9.8), predictable session tokens (CVE-2026-62646, CVE-2026-62647), and pre-auth out-of-bounds writes (CVE-2026-62648). Siemens has released V2.70 and recommends updating to the latest version.