AI analysis
Siemens reports an out-of-bounds write (CWE-787) in the HTTP handling of the Reyrolle 7SR5 protection relay, where the length of the URL component in pre-authenticated HTTP messages is not validated before additional data is appended to it. A remote, unauthenticated attacker can trigger the flaw by sending crafted HTTP messages with an oversized URL directly to the device, corrupting memory and crashing it. The attacker gains a denial-of-service condition: the relay crashes and reboots, interrupting its operation, with no confidentiality or integrity impact per the CVSS 4.0 score (availability impact only). Any Reyrolle 7SR5 unit running a version prior to V2.70 with its HTTP/web interface enabled and reachable by an attacker is affected, though these relays typically sit on utility or industrial OT networks rather than the open internet. There is currently no known exploitation, no public proof-of-concept, and the flaw is not in CISA KEV, with a low EPSS probability (0.3%) of exploitation in the next 30 days.
What to do: Upgrade affected Reyrolle 7SR5 devices to firmware V2.70 or later, per Siemens. Until patched, restrict network access to the relay's HTTP/web management interface so it is reachable only from trusted engineering or SCADA networks, and monitor for unexpected device reboots. Operators of substations or industrial sites using 7SR5 relays should inventory firmware versions and check Siemens' ProductCERT advisory for updates.
Affected
| Siemens Reyrolle 7SR5 | All versions < V2.70 |
Estimated exposure
moderatelikely on the order of thousands to tens of thousands of deployed relays worldwide, but only units with the HTTP management interface reachable from an… — No public install counts are available, so this is estimated from the typical global deployment pattern of Siemens Reyrolle 5-series feeder protection relays across utility substations and industrial power systems, most of which are not…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The length of the URL component contained in pre-authenticated HTTP messages is not properly validated before appending additional data to it, resulting in an out-of-bounds write condition in memory. This could allow an unauthenticated remote attacker to crash the affected device, causing a reboot and resulting in a denial-of-service condition.