AI analysis
Siemens Reyrolle 7SR5 protection relays running firmware before V2.70 fail to properly enforce server-side authorization checks in the web-based management interface (CWE-288). An authenticated, low-privileged remote attacker can bypass role-based access control by manipulating request data, because authorization decisions are not correctly validated on the server. Successful exploitation elevates the attacker from a low-privileged account to administrative level on the device, allowing full management and configuration actions; CVSS 4.0 rates the confidentiality, integrity and availability impact on the vulnerable system as high (8.7). Any Reyrolle 7SR5 unit with the web interface enabled and firmware below V2.70 is affected, typically in utility substation and industrial power deployments where the interface is reachable from an operational network. As of publication there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates a ~0.3% probability of exploitation within 30 days (25th percentile).
What to do: Upgrade Reyrolle 7SR5 firmware to V2.70 or later per the Siemens ProductCert advisory. Until patched, restrict the relay's web management interface to trusted management networks, minimize or remove low-privileged web accounts, and check device configurations/logs for unexpected changes. Exploitation requires valid low-privileged credentials, so account hygiene and network segmentation are the key interim mitigations.
Affected
| Siemens Reyrolle 7SR5 | All versions < V2.70 |
Estimated exposure
unknown (plausibly thousands to tens of thousands of deployed relay devices; no public install or exposure counts) — No public install-count, market-share, or internet-exposure scan data exists for this specialized substation protection relay line, so the magnitude is inferred from deployment patterns: relays are installed per feeder/bay across many…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). Server-side authorization checks in the web-based management interface are not properly enforced, allowing role-based access control (RBAC) restrictions to be bypassed through manipulation of request data. This could allow an authenticated, low-privileged remote attacker to escalate privileges to an administrative level.