ZeroHour

CVE-2026-62649

large

Unauthenticated Resource-Exhaustion DoS in Siemens Reyrolle 7SR5 Relay

CVSS 4.0
8.7 high
EPSS
<1%p26
Published
()
Modified
AI analysis

The embedded web server in Siemens Reyrolle 7SR5 protection relays (CWE-770) fails to properly limit or manage system resources when processing a high volume of concurrent HTTP requests. An unauthenticated remote attacker who can reach the relay's web interface can trigger resource exhaustion with a flood of concurrent requests, causing the entire device to crash and reboot. The attacker gains a denial-of-service condition, and because the 7SR5 is a substation protection relay, its protection function is unavailable while the device crashes and restarts. Any operator running Reyrolle 7SR5 firmware below V2.70 is affected, particularly where the relay's web server is reachable from routable or attacker-accessible networks. No public proof-of-concept, CISA KEV listing, or in-the-wild exploitation is known, and EPSS assigns only a 0.3% probability of exploitation within 30 days.

What to do: Upgrade Reyrolle 7SR5 firmware to V2.70 or later, which resolves the issue; first inventory deployed relays and check their current firmware versions. Until patched, restrict access to the relay's web interface using firewalls/ACLs or a dedicated management network so only trusted hosts can send HTTP requests. Because the impact is loss of the relay's protection function, schedule upgrades within planned maintenance windows where a reboot matters.

Affected
Siemens Reyrolle 7SR5All versions < V2.70
Estimated exposure
largeplausibly on the order of tens of thousands of deployed relays worldwide, of which only units with the web interface network-reachable are practically… — Reyrolle 7SR5 overcurrent protection relays are deployed per feeder/bay in utility and industrial substations globally, implying an installed base in the low tens of thousands, though no public install-base count exists and this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The web server does not properly limit or manage system resources when processing a high volume of concurrent HTTP requests. This could allow an unauthenticated remote attacker to cause the entire device to crash and reboot, resulting in a denial-of-service condition.

Weakness
CWE-770
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

Siemens Reyrolle 7SR5

CISA advisory covers 14 vulnerabilities, CVSS 9.8, in Siemens Reyrolle 7SR5 energy-sector protection relays before V2.70.

CISA advisory ICSA-26-258-05 covers 14 vulnerabilities in Siemens Reyrolle 7SR5 protection relays before V2.70, used in the energy sector worldwide, with aggregate CVSS v3 of 9.8. Flaws include Cesanta Mongoose web server issues (CVE-2024-42384 through CVE-2024-42392) and new bugs such as web-interface session-ID exposure enabling authentication bypass (CVE-2026-62645, CVSS 9.8), predictable session tokens (CVE-2026-62646, CVE-2026-62647), and pre-auth out-of-bounds writes (CVE-2026-62648). Siemens has released V2.70 and recommends updating to the latest version.